• News/
  • https://www.bleepingcomputer.com/news/security/sophos-fixes-sql-injection-vulnerability-in-their-cyberoam-os/

Sophos fixes SQL injection vulnerability in their Cyberoam OS

BleepingComputer
·
Published Dec 10, 2020
·
Updated

Sophos has deployed a hotfix for their line of Cyberoam firewalls and routers to fix a SQL injection vulnerability. Sophos purchased firewall and router maker Cyberoam Technologies in 2014 and has been offering free upgrades to their XG Firewall OS since 2019. Today, Sophos disclosed that a SQL injection vulnerability was fixed in the Cyberoam (CROS) operating system that could remotely add accounts to a CROS device. "A pre-authentication SQL injection vulnerability was recently discovered and fixed on Cyberoam operating system (CROS) devices. This type of vulnerability could allow SQL statements to be executed remotely, but only if the administration interface (HTTPS admin service) was exposed on the WAN zone," the Sophos advisory explains. Sophos has told BleepingComputer that they are currently investigating whether threat actors have exploited this vulnerability. "A small subset of Cyberoam devices were affected by a pre-authentication SQL injection vulnerability and we quickly deployed a hotfix to these devices. No further action is required. More information is available at the Community Page and KBA." "We’ve been phasing out Cyberoam devices since early 2019, and recommend users update to XG Firewall. An easy upgrade path is available that allows Cyberoam users to upgrade their software free of charge," Sophos told BleepingComputer in a statement. This vulnerability does not impact Sophos XG Firewall and SG UTM devices. Sophos has already deployed a hotfix for this vu...

Read full article

Affected Software

1 affected component
Sophos CROS=10.6.6 MR6, =10.6.6 MR5, =10.6.6 MR4, =10.6.6 MR3, =10.6.6 MR2, =10.6.6 MR1, =10.6.6 GA, =10.6.5 MR1, =10.6.5 GA, =10.6.4 MR1, =10.6.4 GA
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a SQL injection vulnerability that was identified and fixed in the Cyberoam OS by Sophos.

2

What security implications are discussed?

The vulnerability could potentially allow attackers to execute malicious SQL commands, compromising the security of affected devices.

3

What products or software are affected by this vulnerability?

The affected products include Sophos Cyberoam firewalls and routers running specific versions of Cyberoam OS.

4

How did Sophos address the vulnerability?

Sophos released a hotfix to rectify the SQL injection vulnerability in their Cyberoam OS.

5

When was Cyberoam Technologies acquired by Sophos?

Sophos purchased Cyberoam Technologies in 2014.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203