LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 6, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 27, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-29574 to its Known Exploited Vulnerabilities catalog on Feb 6, 2025, with a federal patch deadline of Feb 27, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

CVE-2020-29574 is a SQL injection flaw in the WebAdmin interface of Sophos CyberoamOS (also called CROS). An unauthenticated attacker can send crafted input that causes the system to run arbitrary SQL statements remotely. Because the product is end-of-life and end-of-service, continued use leaves organizations without vendor fixes and with a remotely reachable administrative surface that can be abused to read or alter data, escalate privileges, or disrupt operations.

IT and security teams should treat any remaining CyberoamOS deployments as high priority for discovery and removal. Confirm all technical details against the original vendor advisory and CISA guidance before acting.

How it works

The vulnerability belongs to CWE-89 (SQL injection). In this class of flaw, user-controlled input reaches a database query without proper sanitization or parameterization. An attacker who can reach the WebAdmin interface can inject SQL fragments that the application executes with the privileges of the backend database account.

According to the CISA summary, the injection point is in CyberoamOS WebAdmin and requires no authentication. Successful abuse lets the attacker execute arbitrary SQL statements. Typical outcomes for this weakness include dumping credentials or configuration data, modifying firewall or user records, or creating new administrative accounts. Exact request formats, parameters, or payloads are not provided here; teams must obtain those details only from the vendor advisory if they are still available.

Am I affected? How to find it in your systems

CyberoamOS historically ran on Sophos Cyberoam network security appliances that provided firewall, VPN, and web-filtering functions. These devices commonly sit at network perimeters or in branch offices and expose a web-based management console.

Confirm exact management ports and identification strings against any remaining vendor documentation.

How to remediate

CISA’s required action is unambiguous: the product is end-of-life and/or end-of-service, so organizations must discontinue utilization. There is no supported patch path.

If any residual configuration data must be retained for audit, export it offline before the devices are retired.

If you can't patch immediately

Because the product is unsupported, “patching later” is not a viable strategy. Until the devices can be replaced, apply compensating controls that shrink the attack surface:

These measures only reduce risk; they do not eliminate the underlying vulnerability. Schedule decommissioning as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to credential theft, configuration compromise, or broader network intrusion. Known ransomware use of this specific CVE is not documented, yet the remote, unauthenticated nature of the flaw still warrants investigation. Review logs for signs of successful SQL injection, check for unexpected administrative accounts or rule changes, and rotate any credentials that may have been stored on or accessible through the appliance. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSophos · CyberoamOS
WeaknessCWE-89
Added to CISA KEVFeb 6, 2025
Federal patch deadlineFeb 27, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities