logo

SQL Injection Vulnerability SonicWall SMA Appliances

ID: 69b29f68-6d3f-560e-9661-96d4c0b763e4

STIX ID: report--69b29f68-6d3f-560e-9661-96d4c0b763e4

Feed Name: Arctic Wolf Blog

Threat Score
80/100

Date Published: 2021-02-04

Date Updated: 2026-04-26

...
...

Arctic Wolf summarizes SonicWall's disclosure of a zero-day SQL injection (CVE-2021-20016) affecting SMA 100 Series appliances, which enables unauthenticated attackers to extract user credentials and potentially access appliance web interfaces to pivot into networks. SonicWall released firmware 10.2.0.5-29sv to patch the issue; Arctic Wolf recommends updating firmware, resetting passwords, and enabling multifactor authentication, noting researchers have observed exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.