Skip to main content

Vendor/product archive

sonicwall / sma_100_firmware CVEs

Beta · best-effort

13 CVEs tagged to sonicwall / sma_100_firmware2 Critical, 10 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-32821

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the…

CVSS 7.2 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-32820

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writab…

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-32819

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting…

CVSS 8.8 · High
evidence mentions
10
Buzz score
42.0

CVE-2021-20050

Published Dec 23, 2021

An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuratio…

CVSS 7.5 · High

CVE-2021-20049

Published Dec 23, 2021

A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnera…

CVSS 7.5 · High

CVE-2021-20016

Published Feb 4, 2021

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session re…

CVSS 9.8 · Critical
evidence mentions
20
Buzz score
75.0
KEV listed

CVE-2019-7483

Published Dec 19, 2019

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

CVSS 7.5 · High
evidence mentions
2
Buzz score
46.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7481

Published Dec 17, 2019

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVSS 7.5 · High
evidence mentions
8
Buzz score
67.0
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1