FAIL › dossier
SonicWall
VENDOR· dossier confidence 20%
SonicWall is a network security vendor whose SMA100 and SMA1000 appliance lines have suffered a sustained wave of critical RCE, SQL injection, and authentication bypass vulnerabilities. Multiple flaws have been confirmed as actively exploited by CISA and the vendor, indicating a systemic weakness in the security engineering and patch management processes for its core firewall products.
SonicWall has a poor security posture characterized by a high frequency of critical remote code execution (RCE) and SQL injection vulnerabilities across its SMA100 and SMA1000 appliance lines, with multiple flaws added to CISA's Known Exploited Vulnerabilities catalog and active exploitation confirmed by vendors and security researchers.
- CVE-2021-20038: Unauthenticated stack-based buffer overflow RCE on SMA100
- CVE-2025-23006: Unauthenticated deserialization RCE on SMA1000
- CVE-2024-40766: Improper access control RCE linked to ransomware
- CVE-2024-53704: Authentication bypass on SSLVPN
- CVE-2021-20016: Unauthenticated SQL injection for credential access on SMA100
- CVE-2026-15410: Code injection vulnerability on SMA1000
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-09-02 | CVE-2026-83548 | high | SonicWall SMA1000 appliances suffered an actively exploited SSRF vulnerability allowing unauthenticated remote attackers to bypass security controls and perform unauthorized operations. |
| 2026-09-02 | CVE-2026-83549 | high | SonicWall SMA1000 appliances suffered an OS command injection flaw enabling remote authenticated attackers to execute arbitrary commands, resulting in remote code execution. |
| 2025-01-24 | CVE-2025-23006 | critical | SonicWall SMA1000 appliances suffered a deserialization vulnerability allowing remote, unauthenticated attackers to execute arbitrary OS commands. |
| 2025-02-18 | CVE-2024-53704 | critical | SonicWall SonicOS SSLVPN bypassed authentication allowing remote attackers to bypass login. |
| 2024-09-09 | CVE-2024-40766 | critical | SonicWall SonicOS improper access control flaw allowed unauthorized resource access and potential crashes, linked to ransomware. |
| 2022-03-15 | CVE-2020-5135 | high | A remote buffer overflow in SonicWall SonicOS allows attackers to execute arbitrary code and cause denial of service. |
| 2026-07-14 | CVE-2026-15409 | high | SonicWall SMA1000 appliances exposed to unauthenticated server-side request forgery attacks |
| 2026-07-14 | CVE-2026-15410 | high | SonicWall SMA1000 appliances exposed to code injection, allowing remote admin to execute arbitrary commands. |
| 2025-12-17 | CVE-2025-40602 | high | SonicWall SMA1000 exposed to unpatched AMC privilege escalation |
| 2025-04-16 | CVE-2021-20035 | high | SonicWall SMA100 appliances had a command injection vulnerability allowing authenticated attackers to execute arbitrary commands remotely as a low-privilege user. |
| 2022-03-28 | CVE-2021-20028 | critical | SonicWall SRA products had a SQL injection vulnerability actively exploited by ransomware actors, potentially allowing unauthorized data access and system compromise. |
| 2022-01-28 | CVE-2021-20038 | critical | SonicWall SMA 100 appliances had a critical, actively exploited buffer overflow vulnerability allowing code execution without authentication. |
| 2021-11-03 | CVE-2021-20021 | critical | SonicWall Email Security allowed attackers to create administrative accounts via a crafted HTTP request, enabling privilege escalation and ransomware attacks. |
| 2021-11-03 | CVE-2021-20023 | critical | SonicWall Email Security allowed authenticated attackers to read files via a path traversal vulnerability, actively exploited in ransomware attacks. |
| 2021-11-03 | CVE-2021-20016 | critical | SonicWall's SMA100 VPN devices had a SQL injection flaw allowing unauthorized access to credentials, and it was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-20022 | critical | SonicWall Email Security allowed authenticated attackers to upload malicious files, exploited in the wild with ransomware connections. |
| 2021-11-03 | CVE-2019-7481 | critical | SonicWall SMA100 exposed to SQL injection, unauth'd users gained read-only access |
| 2025-05-01 | CVE-2023-44221 | high | SonicWall SMA100 appliances have a critical OS command injection vulnerability allowing authenticated admins to execute arbitrary commands remotely. |
| 2022-03-28 | CVE-2019-7483 | high | SonicWall SMA100 unauthenticated directory traversal flaw lets attackers probe for files on the server. |
| 2025-01-23 | CVE-2025-23006 | critical | CVE-2025-23006: Pre-authentication deserialization of untrusted data vulnerability has been iden |
| 2025-01-09 | CVE-2024-53704 | critical | CVE-2024-53704: An Improper Authentication vulnerability in the SSLVPN authentication mechanism |
| 2021-12-10 | CVE-2021-44228 | critical | CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12 |
| 2021-04-09 | CVE-2021-20021 | critical | CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac |
| 2021-02-04 | CVE-2021-20016 | critical | CVE-2021-20016: A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a re |
"SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025."
"SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution."
"Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks"
"SonicWall reports two major security holes under active exploit"
"SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs"
"Two distinct exploit chains targeting the same vulnerability architecture within two months suggest a persistent structural weakness in the appliance line—and defenders have no IoCs for the latest one."
"Multiple Vulnerabilities have been discovered in SonicWall SMA1000 Series Appliances, which when chained together could allow for remote code execution, potentially leading to full system compromise."
"SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation."
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation."
"SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources."
"SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker."
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation."
"Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution"
"CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks"
"A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information."
"CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware"
- ServiceNow (NOW) Company Profile & Description - Stock Analysis · stockanalysis.com
- Product Notice: SMA 1000 Series affected by Multiple ... - SonicWall · www.sonicwall.com
- U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited ... · securityaffairs.com
- CVE-2026-15409: Patch SonicWall SMA1000 Builds Now · windowsforum.com