CRITICAL
CVE-2020-29574
CVSS
9.8
KEV
Description
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
Summary dbcve.org
An unauthenticated SQL injection vulnerability exists in the WebAdmin interface of Cyberoam OS. Remote attackers can exploit this to execute arbitrary SQL statements, potentially allowing database compromise, credential theft, or full system takeover.
Mitigation
Immediately restrict network access to the WebAdmin interface (it should never be internet-facing) and apply any available vendor patches for Cyberoam OS. If no patch exists, consider compensating controls such as VPN access or moving to a supported platform.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
4.66%
Probability of exploitation in next 30 days
91.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.