logo

SonicWall: SMA100 VPN vulnerabilities now exploited in attacks

ID: 1ca05d23-4519-5d4b-8356-d11d9ad67e56

STIX ID: report--1ca05d23-4519-5d4b-8356-d11d9ad67e56

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-04-30

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SonicWall warned that two vulnerabilities—CVE-2023-44221 (post-auth OS command injection) and CVE-2024-38475 (critical Apache mod_rewrite output-escaping leading to remote code execution)—are potentially being exploited in the wild against SMA 200/210/400/410/500v devices; patches are available in firmware 10.2.1.14-75sv and later. The vendor also flagged an exploitation technique through CVE-2024-38475 that can enable session hijacking, referenced prior active exploitation of CVE-2021-20035, and advised administrators to review devices for unauthorized logins and apply updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.