ZeroHour

CVE-2021-20035

KEVlarge

Authenticated OS Command Injection in SonicWall SMA100 Appliances

CISA: SonicWall SMA100 Appliances OS Command Injection Vulnerability

CVSS 3.1
6.5 medium
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2021-20035 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the management interface of SonicWall SMA100 series appliances. A remote attacker who has authenticated with low-level privileges can inject arbitrary operating system commands, which are executed on the appliance as the 'nobody' user. Per the CVSS scoring, the primary impact is on availability, potentially leading to denial of service, though command execution on the appliance could facilitate further abuse. The flaw affects SMA 200, 210, 400, 410, and 500v firmware. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-16, and related reporting describes ongoing attacks against SonicWall SMA 100 devices — including by threat group UNC6148 deploying the OVERSTEP rootkit and tailored backdoor malware, some against fully patched appliances — so defenders should treat this as actively exploited.

What to do: Patch to the fixed firmware release specified in the SonicWall advisory for your SMA model as soon as possible; federal agencies must follow the BOD 22-01 mitigation deadline per the CISA KEV required action. Restrict the management interface to trusted networks, enforce MFA on the portal, and hunt for signs of compromise such as the OVERSTEP rootkit, unexpected persistence, or unfamiliar accounts, since reporting indicates tailored backdoor malware in recent SMA 100 attacks.

Affected
SonicWall SMA 200 firmware
SonicWall SMA 210 firmware
SonicWall SMA 400 firmware
SonicWall SMA 410 firmware
SonicWall SMA 500v (virtual appliance)
Estimated exposure
large≈ tens of thousands of internet-exposed SMA 100-series appliances (order of magnitude 10k–100k) — Public internet-wide scans of SonicWall SMA/SSL-VPN portals have historically shown tens of thousands of exposed SMA 100-series appliances, and this appliance line is widely deployed by SMBs and enterprises for remote access, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.

CISA Known Exploited Vulnerability
Affected
SonicWall SMA100 Appliances
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sonicwall
Products
sma 200 firmware, sma 210 firmware, sma 400 firmware, sma 410 firmware, sma 500v
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news