Critical severity9.8NVD Advisory· Published Oct 11, 2019· Updated Jun 17, 2026
CVE-2019-17059
CVE-2019-17059
Description
A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:o:sophos:cyberoamos:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:sophos:cyberoamos:*:*:*:*:*:*:*:*range: <10.6.6
- cpe:2.3:o:sophos:cyberoamos:10.6.6:-:*:*:*:*:*:*
- cpe:2.3:o:sophos:cyberoamos:10.6.6:maintenance_release1:*:*:*:*:*:*
- cpe:2.3:o:sophos:cyberoamos:10.6.6:maintenance_release2:*:*:*:*:*:*
- cpe:2.3:o:sophos:cyberoamos:10.6.6:maintenance_release3:*:*:*:*:*:*
- cpe:2.3:o:sophos:cyberoamos:10.6.6:maintenance_release4:*:*:*:*:*:*
- cpe:2.3:o:sophos:cyberoamos:10.6.6:maintenance_release5:*:*:*:*:*:*
- Sophos/CyberoamOSdescription
- Range: <10.6.6 MR-6
Patches
Vulnerability mechanics
References
3- thebestvpn.com/cyberoam-preauth-rce/nvdExploitThird Party Advisory
- community.sophos.com/kb/en-us/134732nvdVendor Advisory
- community.sophos.com/products/cyberoamos/nvdVendor Advisory
News mentions
0No linked articles in our index yet.