Vulnerabilities > Sonicwall > SMA 100 Firmware > 10.2.0.2.20sv

DATE CVE VULNERABILITY TITLE RISK
2025-05-07 CVE-2025-32819 Unspecified vulnerability in Sonicwall products
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
network
low complexity
sonicwall
8.8
2025-05-07 CVE-2025-32820 Unspecified vulnerability in Sonicwall products
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
network
low complexity
sonicwall
8.8
2025-05-07 CVE-2025-32821 Unspecified vulnerability in Sonicwall products
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.
network
low complexity
sonicwall
7.2
2021-02-04 CVE-2021-20016 SQL Injection vulnerability in Sonicwall products
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.
network
low complexity
sonicwall CWE-89
critical
9.8
2021-01-09 CVE-2020-5146 OS Command Injection vulnerability in Sonicwall SMA 100 Firmware
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters.
network
low complexity
sonicwall CWE-78
7.2