← Back to browse · API

CVE-2018-9866

Severity
CRITICAL
CVSS
9.8
EPSS
0.04504
Risk score
40.78
CISA KEV
No
PoC
No
Published
2018-08-03
Modified
2025-05-05
First seen
2026-08-07
Aliases
EUVD-2018-21458, GHSA-29H3-7QGP-VFF3
Products
SonicWall:Global Management System (GMS) 8.1 and earlier
Sources
euvd EUVD-2018-21458

Description

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

References