Sophos has deployed a hotfix for its Cyberoam line of firewalls and routers to fix an SQL injection vulnerability.
Sophos acquired firewall and router manufacturer Cyberoam Technologies in 2014 and has been offering free upgrades to its XG Firewall OS since 2019.
Today, Sophos revealed that an SQL injection vulnerability has been fixed in the Cyberoam Operating System (CROS) that could add accounts to a CROS device.
Sophos told BleepingComputer that they are currently investigating whether hackers have exploited this vulnerability.

This vulnerability does not affect Sophos XG Firewall and SG UTM appliances.
Sophos has already deployed a hotfix for this vulnerability in all supported versions of CROS and affected devices should be updated to the latest version. CROS devices using the “Allow Over-the-air Hotfix” will automatically receive the hotfix on devices .
To check if the hotfix is installed , customers can enter the following command from the CROS console:

Administrators should compare the outgoing version information with the following table to determine whether the hotfix has been added. If the hotfix version number is the same as or greater than the one displayed in the console, this means that the hotfix has been installed.

Sophos also advises administrators to disable WAN to the web admin and SSH interfaces and to check devices for suspicious users.
Source: bleepingcomputer.com
