← Vulnerability feed

Vulnerability record · CVE-2019-7481 · published 17 December 2019

CVE-2019-7481: SonicWall SMA100 SQL injection allows unauthenticated read access

Sonicwall · Sma 100 Firmware

SonicWall SMA100 firmware version 9.0.0.3 and earlier contains a SQL injection flaw (CWE-89) that lets an unauthenticated remote user read resources they are not authorized to access. The vulnerability is network-reachable with no privileges or user interaction required, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-89 · SQL injection
7.5CVSS 3.1 base score, v2 5.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
12 Aug 2026Last modified by NVD

Description

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is unauthenticated, network-reachable, listed in CISA KEV with known ransomware use, and has an EPSS score near 1.0, making exploitation highly likely and impactful.

What it is

SonicWall SMA100 firmware version 9.0.0.3 and earlier contains a SQL injection flaw (CWE-89) that lets an unauthenticated remote user read resources they are not authorized to access. The vulnerability is network-reachable with no privileges or user interaction required, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

Impact

An attacker gains read-only access to unauthorized data on the SMA100 appliance. The CVSS vector shows high confidentiality impact with no integrity or availability effect.

Attack surface

Reachable over the network via the SMA100 interface with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed SMA100 management or portal endpoint is a potential entry point.

Exploitation

CISA added this to the KEV catalog on 2021-11-03 with a 2022-05-03 remediation due date and flags known ransomware campaign use; EPSS probability is 0.99906 (99.966th percentile), indicating very high likelihood of exploitation activity.

What to do

  • Upgrade SMA100 firmware to a version later than 9.0.0.3 per the SonicWall advisory SNWLID-2019-0016.
  • If patching cannot be done immediately, restrict network access to SMA100 interfaces to trusted sources and disable unnecessary exposure to the internet.
  • Monitor and review SMA100 logs for anomalous or unexpected query activity from unauthenticated sessions.
  • Verify remediation against the CISA KEV required action and track completion against the 2022-05-03 due date if still outstanding.

Detection

  • Review SMA100 appliance logs for SQL error messages, malformed query strings, or unusual database access patterns.
  • Alert on unauthenticated requests to SMA100 endpoints that return data outside normal portal behavior.
  • Correlate network traffic to SMA100 with known SQL injection payload signatures in HTTP parameters.
  • Audit for unexpected read access to configuration or user data by sessions lacking valid authentication.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-7481 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall SMA100 SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7481 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20016SonicWall SMA100 SSLVPN SQL injection allows unauthenticated accessSonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to …KEVEPSS 40%analysed7.5CVE-2019-7483SonicWall SMA100 unauthenticated directory traversal in handleWAFRedirect CGISonicWall SMA100 firmware contains an unauthenticated directory traversal flaw in the handleWAFRedirect CGI. The description states the flaw lets a u…KEVEPSS 4.0%analysed9.8CVE-2019-7482Sonicwall sma 100 firmware stack-based buffer overflow vulnerabilityStack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability im…EPSS 8.8%8.8CVE-2025-32819Sonicwall sma 100 firmware vulnerabilityA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitr…EPSS 6.4%8.8CVE-2025-32820Sonicwall sma 100 firmware path traversal vulnerabilityA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directo…EPSS 2.9%8.8CVE-2019-7486Sonicwall sma 100 firmware code injection vulnerabilityCode injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA10…EPSS 1.6%8.8CVE-2019-7485Sonicwall sma 100 firmware classic buffer overflow vulnerabilityBuffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA…EPSS 1.5%7.5CVE-2021-20049Sonicwall sma 100 firmware observable discrepancy vulnerabilityA vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-7481), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.