Executive brief
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface. A remote authenticated attacker can inject arbitrary commands as a 'nobody' user, potentially leading to code execution or denial of service.
Affected products
- SonicWall SMA 200 firmware up to (excluding) 9.0.0.11-31sv, 10.2.0.0 up to (excluding) 10.2.0.8-37sv, 10.2.1.0 up to (excluding) 10.2.1.1-19sv
- SonicWall SMA 210 firmware up to (excluding) 9.0.0.11-31sv, 10.2.0.0 up to (excluding) 10.2.0.8-37sv, 10.2.1.0 up to (excluding) 10.2.1.1-19sv
- SonicWall SMA 400 firmware up to (excluding) 9.0.0.11-31sv, 10.2.0.0 up to (excluding) 10.2.0.8-37sv, 10.2.1.0 up to (excluding) 10.2.1.1-19sv
- SonicWall SMA 410 firmware up to (excluding) 9.0.0.11-31sv, 10.2.0.0 up to (excluding) 10.2.0.8-37sv, 10.2.1.0 up to (excluding) 10.2.1.1-19sv
- SonicWall SMA 500v firmware up to (excluding) 9.0.0.11-31sv, 10.2.0.0 up to (excluding) 10.2.0.8-37sv, 10.2.1.0 up to (excluding) 10.2.1.1-19sv
Timeline
- 2025-04-16: disclosed
- 2025-04-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-04-16: other: Published to NVD