← Back to browse · API

CVE-2021-20039

Severity
HIGH
CVSS
8.8
EPSS
0.7811
Risk score
62.54
CISA KEV
No
PoC
No
Published
2021-12-08
Modified
2025-09-05
First seen
2026-08-07
Aliases
EUVD-2021-7502, GHSA-58FC-493G-JFWJ
Products
SonicWall:SonicWall SMA100 10.2.0.8-37sv and earlier, SonicWall:SonicWall SMA100 10.2.1.1-19sv and earlier, SonicWall:SonicWall SMA100 10.2.1.2-24sv and earlier, SonicWall:SonicWall SMA100 9.0.0.11-31sv and earlier
Sources
euvd EUVD-2021-7502

Description

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

References