← Back

Cyberoam

cyberoam

5 CVEs • 4 products

Products (4)

Click to collapse
Toggle

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cyberoam
1Cyberoamos
May 6, 2026
Sep 4, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml.
1Cyberoam
1Cyberoam Os
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.
1Cyberoam
1Cyberoam Os
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
9.0 HIGH· v2
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) cc...Show more
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.Show less
1Cyberoam
1Cyberoam Os
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.
1Cyberoam
1Cyberoam Central Console
Apr 29, 2026
Feb 12, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file p...Show more
Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action.Show less