OpsBuzz

Alert

CyberoamOS CROS SQL Injection Vulnerability

CyberoamOS CROS contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

Vendor: Sophos

Product: CyberoamOS

Due date: 2025-02-27

Known ransomware use: Unknown

Why it matters

The impacted product is end-of-life EoL and/or end-of-service EoS . Users should discontinue utilization of the product.

Related alerts

CyberoamOS CROS SQL Injection Vulnerability | OpsBuzz