ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Sonicwall SMA100 vulnerability exploited by attackers (CVE-2021-20035)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-20035
Authenticated OS Command Injection in SonicWall SMA100 Appliances

CVE-2021-20035 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the management interface of SonicWall SMA100 series appliances. A remote attacker who has authenticated with low-level privileges can inject arbitrary operating system commands, which are executed on the appliance as the 'nobody' user. Per the CVSS scoring, the primary impact is on availability, potentially leading to denial of service, though command execution on the appliance could facilitate further abuse. The flaw affects SMA 200, 210, 400, 410, and 500v firmware. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-16, and related reporting describes ongoing attacks against SonicWall SMA 100 devices — including by threat group UNC6148 deploying the OVERSTEP rootkit and tailored backdoor malware, some against fully patched appliances — so defenders should treat this as actively exploited.

Do: Patch to the fixed firmware release specified in the SonicWall advisory for your SMA model as soon as possible; federal agencies must follow the BOD 22-01 mitigation deadline per the CISA KEV required action. Restrict the management interface to trusted networks, enforce MFA on the portal, and hunt for signs of compromise such as the OVERSTEP rootkit, unexpected persistence, or unfamiliar accounts, since reporting indicates tailored backdoor malware in recent SMA 100 attacks.

6.54% KEV
  • SonicWall SMA 200 firmware
  • SonicWall SMA 210 firmware
  • SonicWall SMA 400 firmware
  • +2 more
large≈ tens of thousands of internet-exposed SMA 100-series appliances (order of magnitude 10k–100k)
CVE-2025-23006
Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances

CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published.

Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections.

9.823% KEV ransomware
  • SonicWall SMA1000 Appliances — Appliance Management Console (AMC) and Central Management Console (CMC)
largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed
Full article249 words · extracted from helpnetsecurity.com · click to collapse

CVE-2021-20035, an old vulnerability affecting Sonicwall Secure Mobile Access (SMA) 100 series appliances, is being exploited by attackers.

CVE-2021-20035 exploited

Sonicwall confirmed it by updating the original security advisory to reflect the new state of play, and by changing the description of the vulnerability to say that can potentially lead to code execution, instead of only to denial of service (DoS).

About CVE-2021-20035

Sonicwall SMA 100 series appliances provide a unified secure access gateway optimized for small and medium businesses.

CVE-2021-20035 is due to improper neutralization of special elements in the SMA100 management interface and can be exploited by remote authenticated attackers to inject arbitrary OS commands as a “nobody” user.

It affects SMA 100 series appliances, more specifically these models: SMA 200, 210, 400, 410, and 500v (for hybrid-cloud deployments).

Impacted firmware versions include 10.2.1.0-17sv and earlier, 10.2.0.7-34sv and earlier and 9.0.0.10-28sv and earlier.

There are no available workarounds, so admins are advised to upgrade to a fixed version as soon as possible:

  • 10.2.1.1-19sv and higher
  • 10.2.0.8-37sv and higher
  • 9.0.0.11-31sv and higher

Sonicwall SMA appliances are often targeted by attackers via known and zero-day vulnerabilities. Earlier this year, threat actors have been spotted leveraging CVE-2025-23006 as a zero-day to compromise SonicWall SMA 1000 Series appliances.

While both Sonicwall and CISA have confirmed that the CVE-2021-20035 is being exploited, the company has yet to provide details about these latest attacks.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/18/sonicwall-sma100-vulnerability-exploited-by-attackers-cve-2021-20035/