📦

sma_400

Vendor: sonicwall

Actively Exploited 5 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 8 Remote Access
Total CVEs 28 Total Indexed
Avg. EPSS 19.14% Exploit Prob.
Latest CVE CVE-2025-32821 May 07

Security Vulnerability Index

Page 3 / 3
8.8 CVSS

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

EPSS: 82.46%
Critical Target
9.8 CVSS
CVE-2021-20038
RCE Exploit Found

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

EPSS: 94.29%
6.5 CVSS

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.

EPSS: 12.84%
9.1 CVSS
CVE-2021-20034
Exploit Found

An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

EPSS: 5.44%
9.8 CVSS

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

EPSS: 79.82%