CVE detail
CVE-2021-20035
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
The software update includes additional file checks and helps users remove the known rootkit deployed in a recent campaign.
newswww.securityweek.comSep 24, 2025, 8:28 AMSonicWall advises organizations to patch SMA 100 appliances and look for IoCs associated with Overstep malware attacks.
newswww.securityweek.comJul 24, 2025, 10:18 AM- SonicWall SMA devices persistently infected with stealthy OVERSTEP backdoor and rootkitHelp Net Security
Unknown intruders are targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances and deploying a novel, persistent backdoor / rootkit, analysts with Google’s Threat Intelligence Group (GTIG) have warned. The analysts say UNC6148 – as they dubbed the threat group – is likely financially motivated. “An organization targeted by UNC6148 in May 2025 was posted to the ‘World Leaks’ data leak site (DLS) in June 2025, and UNC6148 activity overlaps with publicly … More →
newswww.helpnetsecurity.comJul 16, 2025, 4:52 PM A threat actor that may be financially motivated is targeting SonicWall devices with a backdoor and user-mode rootkit.
newswww.securityweek.comJul 16, 2025, 2:00 PMSonicWall has updated the advisories for two vulnerabilities to warn that they are being exploited in the wild.
newswww.securityweek.comMay 1, 2025, 10:00 AMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Attackers exploited SonicWall SMA appliances since January 2025 ASUS routers with AiCloud vulnerable to auth bypass exploit U.S. […]
newssecurityaffairs.comApr 20, 2025, 9:53 AM- Week in review: LLM package hallucinations harm supply chains, Nagios Log Server flaws fixedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201) Apple has released emergency security updates for iOS/iPadOS, macOS, tvOS and visionOS that fix two zero-day vulnerabilities (CVE-2025-31200, CVE-2025-31201) that have been exploited “in an extremely sophisticated attack against specific targeted individuals on iOS.” When companies merge, so do their cyber threats For CISOs, mergers and acquisitions (M&A) bring … More →
newswww.helpnetsecurity.comApr 20, 2025, 8:00 AM - Attackers exploited SonicWall SMA appliances since January 2025Security Affairs
Threat actors are actively exploiting a remote code execution flaw in SonicWall Secure Mobile Access (SMA) appliances since January 2025. Arctic Wolf researchers warn that threat actors actively exploit a vulnerability, tracked as CVE-2021-20035 (CVSS score of 7.1), in SonicWall Secure Mobile Access (SMA) since at least January 2025. The vulnerability is an OS Command […]
newssecurityaffairs.comApr 19, 2025, 5:37 PM CVE-2021-20035, an old vulnerability affecting Sonicwall Secure Mobile Access (SMA) 100 series appliances, is being exploited by attackers. Sonicwall confirmed it by updating the original security advisory to reflect the new state of play, and by changing the description of the vulnerability to say that can potentially lead to code execution, instead of only to denial of service (DoS). About CVE-2021-20035 Sonicwall SMA 100 series appliances provide a unified secure access gateway optimized for small … More →
newswww.helpnetsecurity.comApr 18, 2025, 11:35 AMA SonicWall SMA 100 series vulnerability patched in 2021, which went unnoticed at the time of patching, is being exploited in the wild.
newswww.securityweek.comApr 17, 2025, 10:10 AM- U.S. CISA adds SonicWall SMA100 Appliance flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall SMA100 Appliance flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SonicWall SMA100 Appliance flaw, tracked as CVE-2021-20035, to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Vulnerability in the SMA100 management interface. A […]
newssecurityaffairs.comApr 17, 2025, 8:30 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-32821CVSS 7.2 · High
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the…
- CVE-2023-44221CVSS 7.2 · High
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary com…
- CVE-2022-22273CVSS 9.8 · Critical
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of…
- CVE-2021-20044CVSS 8.8 · High
A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulner…
- CVE-2021-20039CVSS 8.8 · High
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary comm…
- CVE-2025-32820CVSS 8.8 · High
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writab…