logo
Home/CVEs/CVE-2021-20035/

CVE-2021-20035 - SonicWall SMA100 Appliances OS Command Injection Vulnerability

Project:SonicWall

Product:SMA100 Appliances

Date Added:2025-04-16Due Date:2025-05-07

Vulnerability Name

SonicWall SMA100 Appliances OS Command Injection Vulnerability

Description

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022

https://nvd.nist.gov/vuln/detail/CVE-2021-20035

Related News Articles

SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as RootMay 8, 2025

SonicWall urges admins to patch VPN flaw exploited in attacksMay 8, 2025

SonicWall warns of more VPN flaws exploited in attacksMay 1, 2025

SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance ModelsMay 1, 2025

SonicWall: SMA100 VPN vulnerabilities now exploited in attacksMay 1, 2025