CVE-2021-20035 - SonicWall SMA100 Appliances OS Command Injection Vulnerability
Project:SonicWall
Product:SMA100 Appliances
Date Added:2025-04-16Due Date:2025-05-07
Vulnerability Name
SonicWall SMA100 Appliances OS Command Injection Vulnerability
Description
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022
https://nvd.nist.gov/vuln/detail/CVE-2021-20035
Related News Articles
SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as RootMay 8, 2025
SonicWall urges admins to patch VPN flaw exploited in attacksMay 8, 2025
SonicWall warns of more VPN flaws exploited in attacksMay 1, 2025
SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance ModelsMay 1, 2025
SonicWall: SMA100 VPN vulnerabilities now exploited in attacksMay 1, 2025