Sophos: Vulnerability Affecting Cyberoam Appliances
A SQL injection vulnerability has been discovered in Cyberoam appliances running the Cyberoam operating system (CROS) that allows for unauthenticated remote code execution.
A small percentage of appliances have been impacted by a cryptominer that consumed CPU cycles. Our investigations have found no evidence that any data has been compromised or exfiltrated from those appliances.
For customers running CROS version 10.6.1 and above that use the default setting of automatic updates, the hotfix was automatically installed, and there is no action required. Customers who have changed their default settings will need to apply the update manually.
For more information please read the following KBA on our support website: https://community.sophos.com/kb/en-us/127958.