CVE-2020-29574
KEV ransomwarelargeUnauthenticated SQL Injection in Sophos CyberoamOS WebAdmin
CISA: CyberoamOS (CROS) SQL Injection Vulnerability
CVE-2020-29574 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in the WebAdmin management console of Sophos CyberoamOS (CROS), the operating system of Cyberoam network security appliances acquired by Sophos. An unauthenticated remote attacker can send crafted requests to the exposed WebAdmin interface and execute arbitrary SQL statements against the backend database, with no credentials or user interaction required. Successful exploitation can reveal or alter firewall management data and facilitate further compromise; CISA notes it is being used in ransomware operations. Any organization still running a CyberoamOS appliance is affected, and CISA flags the product as end-of-life/end-of-service, so no current support exists. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06; no public PoC is known, but exploitation in the wild is confirmed.
What to do: Because CyberoamOS is end-of-life/end-of-service, CISA's required action is to discontinue use: migrate Cyberoam appliances to a currently supported Sophos Firewall release or retire them. Until migration, restrict WebAdmin access to trusted management networks rather than the public internet, review appliance logs for unexpected administrative or database activity, and hunt for signs of compromise given the known ransomware use.
| Sophos CyberoamOS (CROS) - WebAdmin | all versions through 2020-12-04 (CISA date-based range); product is EoL/EoS |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
- Affected
- Sophos CyberoamOS
- Required action
- The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
- Due date
- Ransomware use
- Known
- Vendors
- sophos
- Products
- cyberoamos
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H