SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20035 | Authenticated OS Command Injection in SonicWall SMA100 Appliances CVE-2021-20035 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the management interface of SonicWall SMA100 series appliances. A remote attacker who has authenticated with low-level privileges can inject arbitrary operating system commands, which are executed on the appliance as the 'nobody' user. Per the CVSS scoring, the primary impact is on availability, potentially leading to denial of service, though command execution on the appliance could facilitate further abuse. The flaw affects SMA 200, 210, 400, 410, and 500v firmware. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-16, and related reporting describes ongoing attacks against SonicWall SMA 100 devices — including by threat group UNC6148 deploying the OVERSTEP rootkit and tailored backdoor malware, some against fully patched appliances — so defenders should treat this as actively exploited. Do: Patch to the fixed firmware release specified in the SonicWall advisory for your SMA model as soon as possible; federal agencies must follow the BOD 22-01 mitigation deadline per the CISA KEV required action. Restrict the management interface to trusted networks, enforce MFA on the portal, and hunt for signs of compromise such as the OVERSTEP rootkit, unexpected persistence, or unfamiliar accounts, since reporting indicates tailored backdoor malware in recent SMA 100 attacks. | 6.5 | 4% | KEV |
| large≈ tens of thousands of internet-exposed SMA 100-series appliances (order of magnitude 10k–100k) | |
| CVE-2023-44221 | OS Command Injection in SonicWall SMA100 SSL-VPN Management Interface SonicWall SMA100 appliances contain an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the SSL-VPN management interface. A remote attacker who is already authenticated with administrative privileges can submit crafted input containing special characters, causing arbitrary operating system commands to be executed on the appliance. Injected commands run as the low-privilege 'nobody' user, which limits immediate access but still yields high-impact confidentiality, integrity, and availability outcomes (CVSS 7.2) and can provide a foothold for further compromise. Affected products are the SMA 200, SMA 210, SMA 400, and SMA 410 appliance firmware and the SMA 500v virtual appliance firmware. The flaw carries a high EPSS score (75.1%, 99th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01, and reporting indicates both SonicWall and CISA have confirmed active in-the-wild exploitation of this and related SMA100 flaws. Do: Upgrade affected SMA100 appliances (SMA 200/210/400/410 and SMA 500v) to the latest vendor-patched firmware per SonicWall's advisory, as required under CISA KEV/BOD 22-01 timelines. Until patched, restrict access to the SSL-VPN management interface to trusted networks and enforce MFA on administrative accounts, since exploitation requires an authenticated administrative session. Given confirmed in-the-wild exploitation, review appliance logs for unauthorized administrative activity or command execution and rotate credentials if compromise is suspected. | 7.2 | 76% | KEV |
| large≈tens of thousands of internet-exposed SMA100 SSL-VPN appliances (order 10k–100k) | |
| CVE-2024-38475 | Improper Output Escaping in Apache HTTP Server mod_rewrite Enables File Disclosure/Code Execution CVE-2024-38475 is an improper escaping of output flaw (CWE-116) in the mod_rewrite module of the Apache HTTP Server. It is triggered when mod_rewrite maps a request URL to a filesystem location and mishandles encoded characters, allowing a crafted request to reach files that the server is permitted to serve but that were never intentionally or directly reachable by any URL. An attacker can abuse this to disclose source code (for example, serving raw application files) or, depending on the server's configuration and handlers, achieve code execution. Any Apache HTTP Server deployment that uses mod_rewrite is potentially affected; the source data does not specify the vulnerable version range. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Inventory Apache HTTP Server deployments, prioritize internet-facing ones, and check whether mod_rewrite is in use (RewriteRule directives in server config, virtual hosts, or .htaccess files); upgrade to the vendor's fixed release, 2.4.60 or later. If immediate upgrade is not possible, follow vendor guidance to harden or constrain mod_rewrite rules, and treat the issue as actively exploited per CISA KEV, applying BOD 22-01 mitigations for cloud service usage or discontinuing use if mitigation is unavailable. | 9.1 | 100% | KEV |
| masslikely hundreds of thousands to over a million internet-exposed Apache HTTP Server instances, with only the mod_rewrite-enabled subset vulnerable | |
| CVE-2025-32819 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file po A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. NVD description · AI analysis pending | 8.8 group max | 6% | PoC |
| — |
Full article342 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 08, 2025Network Security / Vulnerability
SonicWall has released patches to address three security flaws affecting SMA 100 Secure Mobile Access (SMA) appliances that could be fashioned to result in remote code execution.
The vulnerabilities are listed below -
- CVE-2025-32819 (CVSS score: 8.8) - A vulnerability in SMA100 allows a remote authenticated attacker with SSL-VPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
- CVE-2025-32820 (CVSS score: 8.3) - A vulnerability in SMA100 allows a remote authenticated attacker with SSL-VPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable
- CVE-2025-32821 (CVSS score: 6.7) - A vulnerability in SMA100 allows a remote authenticated attacker with SSL-VPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance
"An attacker with access to an SMA SSL-VPN user account can chain these vulnerabilities to make a sensitive system directory writable, elevate their privileges to SMA administrator, and write an executable file to a system directory," Rapid7 said in a report. "This chain results in root-level remote code execution."
CVE-2025-32819 is assessed to be a patch bypass for a previously identified flaw reported by NCC Group in December 2021.
The cybersecurity company noted that CVE-2025-32819 may have been exploited in the wild as a zero-day based on known indicators of compromise (IoCs) and incident response investigations. However, it's worth noting that SonicWall makes no mention of the flaw being weaponized in real-world attacks.
The shortcomings, that impact SMA 100 Series including SMA 200, 210, 400, 410, 500v, have been addressed in version 10.2.1.15-81sv.
The development comes as multiple security flaws in SMA 100 Series devices have come under active exploitation in recent weeks, including CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475. Users are advised to update their instances to the latest version for optimal protection.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/05/sonicwall-patches-3-flaws-in-sma-100.html