CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

sonicwall

sma_100_firmware

13 known vulnerabilities · sorted by CVSS score

CVE-2019-7482
CRITICAL9.8

Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

sonicwall / sma_100_firmware
Network
Published Dec 19, 2019
CVE-2021-20016
CRITICAL9.8

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

sonicwall / sma_100_firmware+5
Network
Published Feb 4, 2021
CVE-2019-7486
HIGH8.8

Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.

sonicwall / sma_100_firmware
Network
Published Dec 19, 2019
CVE-2019-7485
HIGH8.8

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

sonicwall / sma_100_firmware
Network
Published Dec 19, 2019
CVE-2025-32819
HIGH8.8

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

sonicwall / sma_100_firmware+5
Network
Published May 7, 2025
CVE-2025-32820
HIGH8.8

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.

sonicwall / sma_100_firmware+5
Network
Published May 7, 2025
CVE-2019-7483
HIGH7.5

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

sonicwall / sma_100_firmware
Network
Published Dec 19, 2019
CVE-2021-20049
HIGH7.5

A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.

sonicwall / sma_100_firmware+17
Network
Published Dec 23, 2021
CVE-2021-20050
HIGH7.5

An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.

sonicwall / sma_100_firmware+17
Network
Published Dec 23, 2021
CVE-2019-7481
HIGH7.5

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

sonicwall / sma_100_firmware
Network
Published Dec 17, 2019
CVE-2020-5146
HIGH7.2

A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.

sonicwall / sma_100_firmware
Network
Published Jan 9, 2021
CVE-2025-32821
HIGH7.2

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

sonicwall / sma_100_firmware+5
Network
Published May 7, 2025
CVE-2019-7484
MEDIUM6.5

Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

sonicwall / sma_100_firmware
Network
Published Dec 19, 2019