← Vulnerability feed

Vulnerability record · CVE-2019-7483 · published 19 December 2019

CVE-2019-7483: SonicWall SMA100 unauthenticated directory traversal in handleWAFRedirect CGI

Sonicwall · Sma 100 Firmware

SonicWall SMA100 firmware contains an unauthenticated directory traversal flaw in the handleWAFRedirect CGI. The description states the flaw lets a user test for the presence of a file on the server, so it is an information-disclosure issue rather than direct code execution. It matters because the endpoint is reachable without credentials and the product is an internet-facing remote access appliance.

7.5 CVSS 3.1 High CISA KEV since 28 Mar 2022 EPSS 4.0% · top 9.8% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
4.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCVSS 7.5 with no authentication required and confirmed exploitation per CISA KEV, though impact is limited to file-presence disclosure.

What it is

SonicWall SMA100 firmware contains an unauthenticated directory traversal flaw in the handleWAFRedirect CGI. The description states the flaw lets a user test for the presence of a file on the server, so it is an information-disclosure issue rather than direct code execution. It matters because the endpoint is reachable without credentials and the product is an internet-facing remote access appliance.

Impact

An attacker can probe the server for the existence of files, gaining reconnaissance information about the appliance. The record does not indicate file contents are read, only that file presence can be tested.

Attack surface

Reached over the network via the handleWAFRedirect CGI on the SMA100 web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

It is listed in CISA KEV (added 2022-03-28), indicating known exploitation in the wild; EPSS 30-day probability is about 4.0 percent (90th percentile). No ransomware campaign use is recorded.

What to do

  • Apply the vendor update referenced in SonicWall advisory SNWLID-2019-0018, following CISA's required action.
  • Restrict or block external access to the SMA100 management/web interface where operationally possible.
  • Monitor and log requests to the handleWAFRedirect CGI endpoint.
  • If patching is delayed, place the appliance behind filtering that blocks traversal sequences in request paths.

Detection

  • Search web/proxy logs for requests to handleWAFRedirect containing traversal sequences such as ../ or encoded variants.
  • Alert on unauthenticated requests to CGI endpoints on SMA100 appliances from unexpected source IPs.
  • Correlate repeated file-probing requests from a single source against the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-7483 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "SonicWall SMA100 Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7483 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20016SonicWall SMA100 SSLVPN SQL injection allows unauthenticated accessSonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to …KEVEPSS 40%analysed7.5CVE-2019-7481SonicWall SMA100 SQL injection allows unauthenticated read accessSonicWall SMA100 firmware version 9.0.0.3 and earlier contains a SQL injection flaw (CWE-89) that lets an unauthenticated remote user read resources …KEVEPSS 100%analysed9.8CVE-2019-7482Sonicwall sma 100 firmware stack-based buffer overflow vulnerabilityStack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability im…EPSS 8.8%8.8CVE-2025-32819Sonicwall sma 100 firmware vulnerabilityA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitr…EPSS 6.4%8.8CVE-2025-32820Sonicwall sma 100 firmware path traversal vulnerabilityA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directo…EPSS 2.9%8.8CVE-2019-7486Sonicwall sma 100 firmware code injection vulnerabilityCode injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA10…EPSS 1.6%8.8CVE-2019-7485Sonicwall sma 100 firmware classic buffer overflow vulnerabilityBuffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA…EPSS 1.5%7.5CVE-2021-20049Sonicwall sma 100 firmware observable discrepancy vulnerabilityA vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-7483), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.