← Vulnerability feed

Vulnerability record · CVE-2019-7486 · published 19 December 2019

CVE-2019-7486: Sonicwall sma 100 firmware code injection vulnerability

Sonicwall · Sma 100 Firmware

Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.

8.8 CVSS 3.1 High EPSS 1.6% · top 25.5% CWE-94 · Code injection
8.8CVSS 3.1 base score, v2 6.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7486 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20016SonicWall SMA100 SSLVPN SQL injection allows unauthenticated accessSonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to …KEVEPSS 40%analysed7.5CVE-2019-7483SonicWall SMA100 unauthenticated directory traversal in handleWAFRedirect CGISonicWall SMA100 firmware contains an unauthenticated directory traversal flaw in the handleWAFRedirect CGI. The description states the flaw lets a u…KEVEPSS 4.0%analysed7.5CVE-2019-7481SonicWall SMA100 SQL injection allows unauthenticated read accessSonicWall SMA100 firmware version 9.0.0.3 and earlier contains a SQL injection flaw (CWE-89) that lets an unauthenticated remote user read resources …KEVEPSS 100%analysed9.8CVE-2019-7482Sonicwall sma 100 firmware stack-based buffer overflow vulnerabilityStack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability im…EPSS 8.8%8.8CVE-2025-32819Sonicwall sma 100 firmware vulnerabilityA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitr…EPSS 6.4%8.8CVE-2025-32820Sonicwall sma 100 firmware path traversal vulnerabilityA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directo…EPSS 2.9%8.8CVE-2019-7485Sonicwall sma 100 firmware classic buffer overflow vulnerabilityBuffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA…EPSS 1.5%7.5CVE-2021-20049Sonicwall sma 100 firmware observable discrepancy vulnerabilityA vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-7486), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.