CVE-2021-20035CISA KEVEPSS p88.9%

CVE-2021-20035SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall / SMA100 Appliances

Description

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

Scoring

EPSS3.89% probability of exploitation · percentile 88.9% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2025-04-16

(incoming)1

TypeTargetConfidenceTier
KEVEntrySonicWall SMA100 Appliances OS Command Injection Vulnerabilitykev-cve-2021-200350%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
CVE
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
CVE
SonicWall SMA100 SQL Injection Vulnerability
CVE
SonicWall SMA1000 Appliances Deserialization Vulnerability
CVE
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
CVE
SonicWall SMA1000 Missing Authorization Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.