FAIL › dossier
SonicWall
VENDOR· dossier confidence 20%
SonicWall is a network security vendor whose SMA100 and SMA1000 appliance lines have suffered a sustained wave of critical RCE, SQL injection, and authentication bypass vulnerabilities. Multiple flaws have been confirmed as actively exploited by CISA and the vendor, indicating a systemic weakness in the security engineering and patch management processes for its core firewall products.
SonicWall has a poor security posture characterized by a high frequency of critical remote code execution (RCE) and SQL injection vulnerabilities across its SMA100 and SMA1000 appliance lines, with multiple flaws added to CISA's Known Exploited Vulnerabilities catalog and active exploitation confirmed by vendors and security researchers.
- CVE-2021-20038: Unauthenticated stack-based buffer overflow RCE on SMA100
- CVE-2025-23006: Unauthenticated deserialization RCE on SMA1000
- CVE-2024-40766: Improper access control RCE linked to ransomware
- CVE-2024-53704: Authentication bypass on SSLVPN
- CVE-2021-20016: Unauthenticated SQL injection for credential access on SMA100
- CVE-2026-15410: Code injection vulnerability on SMA1000
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-01-24 | CVE-2025-23006 | critical | SonicWall SMA1000 appliances suffered a deserialization vulnerability allowing remote, unauthenticated attackers to execute arbitrary OS commands. |
| 2025-02-18 | CVE-2024-53704 | critical | SonicWall SonicOS SSLVPN bypassed authentication allowing remote attackers to bypass login. |
| 2024-09-09 | CVE-2024-40766 | critical | SonicWall SonicOS improper access control flaw allowed unauthorized resource access and potential crashes, linked to ransomware. |
| 2022-03-15 | CVE-2020-5135 | high | A remote buffer overflow in SonicWall SonicOS allows attackers to execute arbitrary code and cause denial of service. |
| 2026-07-14 | CVE-2026-15409 | high | SonicWall SMA1000 appliances exposed to unauthenticated server-side request forgery attacks |
| 2026-07-14 | CVE-2026-15410 | high | SonicWall SMA1000 appliances exposed to code injection, allowing remote admin to execute arbitrary commands. |
| 2025-12-17 | CVE-2025-40602 | high | SonicWall SMA1000 exposed to unpatched AMC privilege escalation |
| 2025-04-16 | CVE-2021-20035 | high | SonicWall SMA100 appliances had a command injection vulnerability allowing authenticated attackers to execute arbitrary commands remotely as a low-privilege user. |
| 2022-03-28 | CVE-2021-20028 | critical | SonicWall SRA products had a SQL injection vulnerability actively exploited by ransomware actors, potentially allowing unauthorized data access and system compromise. |
| 2022-01-28 | CVE-2021-20038 | critical | SonicWall SMA 100 appliances had a critical, actively exploited buffer overflow vulnerability allowing code execution without authentication. |
| 2021-11-03 | CVE-2019-7481 | critical | SonicWall SMA100 exposed to SQL injection, unauth'd users gained read-only access |
| 2021-11-03 | CVE-2021-20021 | critical | SonicWall Email Security allowed attackers to create administrative accounts via a crafted HTTP request, enabling privilege escalation and ransomware attacks. |
| 2021-11-03 | CVE-2021-20022 | critical | SonicWall Email Security allowed authenticated attackers to upload malicious files, exploited in the wild with ransomware connections. |
| 2021-11-03 | CVE-2021-20023 | critical | SonicWall Email Security allowed authenticated attackers to read files via a path traversal vulnerability, actively exploited in ransomware attacks. |
| 2021-11-03 | CVE-2021-20016 | critical | SonicWall's SMA100 VPN devices had a SQL injection flaw allowing unauthorized access to credentials, and it was actively exploited in the wild. |
| 2025-05-01 | CVE-2023-44221 | high | SonicWall SMA100 appliances have a critical OS command injection vulnerability allowing authenticated admins to execute arbitrary commands remotely. |
| 2022-03-28 | CVE-2019-7483 | high | SonicWall SMA100 unauthenticated directory traversal flaw lets attackers probe for files on the server. |
| 2025-01-23 | CVE-2025-23006 | critical | CVE-2025-23006: Pre-authentication deserialization of untrusted data vulnerability has been iden |
| 2025-01-09 | CVE-2024-53704 | critical | CVE-2024-53704: An Improper Authentication vulnerability in the SSLVPN authentication mechanism |
| 2021-12-10 | CVE-2021-44228 | critical | CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12 |
| 2021-04-09 | CVE-2021-20021 | critical | CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac |
| 2021-02-04 | CVE-2021-20016 | critical | CVE-2021-20016: A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a re |
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation."
"SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation."
"SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources."
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation."
"SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker."
"A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information."
"CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware"
"Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution"
"CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks"
- ServiceNow (NOW) Company Profile & Description - Stock Analysis · stockanalysis.com
- Product Notice: SMA 1000 Series affected by Multiple ... - SonicWall · www.sonicwall.com
- U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited ... · securityaffairs.com
- CVE-2026-15409: Patch SonicWall SMA1000 Builds Now · windowsforum.com