Skip to content
COOEY

FAIL › dossier

SonicWall

VENDOR

· dossier confidence 20%

SonicWall is a network security vendor whose SMA100 and SMA1000 appliance lines have suffered a sustained wave of critical RCE, SQL injection, and authentication bypass vulnerabilities. Multiple flaws have been confirmed as actively exploited by CISA and the vendor, indicating a systemic weakness in the security engineering and patch management processes for its core firewall products.

PROFILE
CategoryNetwork Security / FirewallWhat they doSonicWall provides network security appliances, firewalls, and secure remote access solutions for enterprise and small-to-medium businesses. Websitehttps://www.sonicwall.com ↗
SECURITY POSTURE

SonicWall has a poor security posture characterized by a high frequency of critical remote code execution (RCE) and SQL injection vulnerabilities across its SMA100 and SMA1000 appliance lines, with multiple flaws added to CISA's Known Exploited Vulnerabilities catalog and active exploitation confirmed by vendors and security researchers.

Notable failures
  • CVE-2021-20038: Unauthenticated stack-based buffer overflow RCE on SMA100
  • CVE-2025-23006: Unauthenticated deserialization RCE on SMA1000
  • CVE-2024-40766: Improper access control RCE linked to ransomware
  • CVE-2024-53704: Authentication bypass on SSLVPN
  • CVE-2021-20016: Unauthenticated SQL injection for credential access on SMA100
  • CVE-2026-15410: Code injection vulnerability on SMA1000
Patterns: Repeated critical RCE vulnerabilities in SMA100/SMA1000 management interfaces; Unauthenticated SQL injection flaws enabling credential theft; Authentication bypasses in SSLVPN and management consoles; Vulnerabilities added to CISA Known Exploited Vulnerabilities catalog
FAILURE HISTORY · 22
DATEEVENTSEVSUMMARY
2025-01-24 CVE-2025-23006 critical SonicWall SMA1000 appliances suffered a deserialization vulnerability allowing remote, unauthenticated attackers to execute arbitrary OS commands.
2025-02-18 CVE-2024-53704 critical SonicWall SonicOS SSLVPN bypassed authentication allowing remote attackers to bypass login.
2024-09-09 CVE-2024-40766 critical SonicWall SonicOS improper access control flaw allowed unauthorized resource access and potential crashes, linked to ransomware.
2022-03-15 CVE-2020-5135 high A remote buffer overflow in SonicWall SonicOS allows attackers to execute arbitrary code and cause denial of service.
2026-07-14 CVE-2026-15409 high SonicWall SMA1000 appliances exposed to unauthenticated server-side request forgery attacks
2026-07-14 CVE-2026-15410 high SonicWall SMA1000 appliances exposed to code injection, allowing remote admin to execute arbitrary commands.
2025-12-17 CVE-2025-40602 high SonicWall SMA1000 exposed to unpatched AMC privilege escalation
2025-04-16 CVE-2021-20035 high SonicWall SMA100 appliances had a command injection vulnerability allowing authenticated attackers to execute arbitrary commands remotely as a low-privilege user.
2022-03-28 CVE-2021-20028 critical SonicWall SRA products had a SQL injection vulnerability actively exploited by ransomware actors, potentially allowing unauthorized data access and system compromise.
2022-01-28 CVE-2021-20038 critical SonicWall SMA 100 appliances had a critical, actively exploited buffer overflow vulnerability allowing code execution without authentication.
2021-11-03 CVE-2019-7481 critical SonicWall SMA100 exposed to SQL injection, unauth'd users gained read-only access
2021-11-03 CVE-2021-20021 critical SonicWall Email Security allowed attackers to create administrative accounts via a crafted HTTP request, enabling privilege escalation and ransomware attacks.
2021-11-03 CVE-2021-20022 critical SonicWall Email Security allowed authenticated attackers to upload malicious files, exploited in the wild with ransomware connections.
2021-11-03 CVE-2021-20023 critical SonicWall Email Security allowed authenticated attackers to read files via a path traversal vulnerability, actively exploited in ransomware attacks.
2021-11-03 CVE-2021-20016 critical SonicWall's SMA100 VPN devices had a SQL injection flaw allowing unauthorized access to credentials, and it was actively exploited in the wild.
2025-05-01 CVE-2023-44221 high SonicWall SMA100 appliances have a critical OS command injection vulnerability allowing authenticated admins to execute arbitrary commands remotely.
2022-03-28 CVE-2019-7483 high SonicWall SMA100 unauthenticated directory traversal flaw lets attackers probe for files on the server.
2025-01-23 CVE-2025-23006 critical CVE-2025-23006: Pre-authentication deserialization of untrusted data vulnerability has been iden
2025-01-09 CVE-2024-53704 critical CVE-2024-53704: An Improper Authentication vulnerability in the SSLVPN authentication mechanism
2021-12-10 CVE-2021-44228 critical CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
2021-04-09 CVE-2021-20021 critical CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac
2021-02-04 CVE-2021-20016 critical CVE-2021-20016: A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a re
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability allows attacker to create admin account via crafted HTTP request, part of known exploit chain for privilege escalation.
synthesissevere-fallout-0.60
Vulnerability exploited in known chains for privilege escalation, indicating severe security failure.
synthesissevere-fallout-0.60
Unauthenticated SQL injection allowing credential theft is a severe security failure, though the provided source is purely factual without commentary on SonicWall's response or industry reaction.
synthesissevere-fallout-0.60
Vulnerability allowed privilege escalation via known exploit chains, indicating severe security failure.
synthesissevere-fallout-0.60
SonicWall faced severe fallout for an unauthenticated SQL injection flaw in SMA100, exposing unauthorized read-only access.
synthesissevere-fallout-0.60
SonicWall faced severe fallout due to actively exploited critical vulnerabilities in its SMA1000 and GMS products, with CISA adding them to the KEV catalog and reports of ransomware deployments, indic
cooey ↗severe-fallout-0.60
Vulnerability exploited in known chains for privilege escalation, indicating severe security failure.
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation."
cooey ↗severe-fallout-0.60
Vulnerability allows attacker to create admin account via crafted HTTP request, part of known exploit chain for privilege escalation.
"SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation."
cooey ↗severe-fallout-0.60
SonicWall faced severe fallout for an unauthenticated SQL injection flaw in SMA100, exposing unauthorized read-only access.
"SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources."
cooey ↗severe-fallout-0.60
Vulnerability allowed privilege escalation via known exploit chains, indicating severe security failure.
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation."
cooey ↗severe-fallout+0.00
neutral
"SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker."
cooey ↗severe-fallout-0.80
Severe vulnerability allowing unauthenticated SQL injection to access credentials, representing a critical failure in SonicWall's product security.
"A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information."
cybersecuritynews.com ↗severe-fallout-0.90
SonicWall vulnerabilities exploited in ransomware attacks, with CISA marking them as known to be used in ransomware campaigns, indicating severe fallout and active exploitation.
"CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware"
CISA ↗severe-fallout+0.00
Neutral; CISA's advisory page provides general cybersecurity guidance without specific commentary on SonicWall's handling of the vulnerability.
www.cisecurity.org ↗severe-fallout-0.80
SonicWall GMS vulnerabilities could allow remote code execution, indicating severe fallout and critical security failures in SonicWall's management interface.
"Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution"
cvefeed.io ↗severe-fallout+0.00
Neutral; CVEFeed provides a catalog of CISA KEV without specific commentary on SonicWall's handling of the vulnerability.
cyberpress.org ↗severe-fallout-0.90
CISA actively exploited critical SonicWall SMA1000 SSRF flaw in zero-day attacks, indicating severe fallout and active exploitation of SonicWall's vulnerabilities.
"CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks"
www.cvefind.com ↗severe-fallout+0.00
Neutral; CVE Find provides a database of vulnerabilities without specific commentary on SonicWall's handling of the vulnerability.
Open questions: Current patch status for CVE-2025-23006 and CVE-2024-53704 · SonicWall's incident response timeline for critical RCE CVEs
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:57:11.420161+00:00