logo

Credential Access Campaign Targeting SonicWall SMA Devices Potentially Linked to Exploitation of CVE-2021-20035

ID: bccb2672-8998-5770-b19c-38d23b7ebc15

STIX ID: report--bccb2672-8998-5770-b19c-38d23b7ebc15

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2025-04-17

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

**Arctic Wolf reports an active campaign (Jan–Apr 2025) targeting SonicWall SMA 100 series appliances leveraging CVE-2021-20035 (recently updated to indicate RCE, CVSS 7.2) and weak/default local credentials to obtain VPN access and persistence; SonicWall confirmed in-the-wild exploitation and the issue was added to CISA’s KEV catalog. Recommended mitigations include applying vendor fixes, enforcing MFA, resetting and hardening local passwords, disabling unneeded accounts, limiting VPN access, and enabling syslog monitoring for detection.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.