CyberoamOS (CROS) SQL Injection Vulnerability
Vendor: Sophos
Product: CyberoamOS
Added: 2025-02-06
Due Date: 2025-02-27
Description:
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
Required Action:
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CWEs: