← Vulnerability feed

Vulnerability record · CVE-2021-20028 · published 4 August 2021

CVE-2021-20028: SonicWall SRA appliances SQL injection in end-of-life firmware

Sonicwall · Sma 210 Firmware

SonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL injection. The affected products are end-of-life, so no fix path exists and exposure persists wherever these appliances remain deployed.

9.8 CVSS 3.1 Critical CISA KEV since 28 Mar 2022 Known ransomware use EPSS 30% · top 1.8% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
30%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote SQL injection on internet-facing remote access appliances, listed in KEV with known ransomware use and no patch available for end-of-life hardware.

What it is

SonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL injection. The affected products are end-of-life, so no fix path exists and exposure persists wherever these appliances remain deployed.

Impact

An unauthenticated remote attacker can inject SQL to read or alter backend data and potentially execute commands in the appliance context, compromising the remote access gateway itself.

Attack surface

Reachable over the network via the appliance's web interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Listed in CISA KEV since 2022-03-28 with known ransomware campaign use, and EPSS shows a 30-day probability of about 30 percent (98th percentile), indicating active exploitation.

What to do

  • Disconnect or retire any end-of-life SRA appliance still in use, as CISA and the vendor require; there is no supported patch for these models.
  • If immediate removal is impossible, isolate the appliance from the internet and restrict management and user access to trusted networks only.
  • Migrate remote access to a supported SonicWall SMA or other maintained VPN/SSL-VPN platform.
  • Audit for signs of prior compromise before decommissioning, since the device may already be backdoored.

Detection

  • Search web or WAF logs for SQL metacharacters and injection patterns in requests to SRA login and portal endpoints.
  • Monitor appliance and adjacent systems for unexpected outbound connections, new accounts, or configuration changes.
  • Hunt for known post-exploitation artifacts on the appliance and internal hosts that communicated with it.
  • Inventory the network for SRA 8.x and 9.0.0.9-26sv or earlier firmware to confirm remaining exposure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-20028 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 18 April 2022.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20038SonicWall SMA 100 appliances stack buffer overflow in mod_cgiA stack-based buffer overflow in the Apache httpd mod_cgi module of SonicWall SMA 100 series appliances lets a remote unauthenticated attacker overwr…KEVEPSS 100%analysed9.8CVE-2021-20016SonicWall SMA100 SSLVPN SQL injection allows unauthenticated accessSonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to …KEVEPSS 40%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed7.2CVE-2023-44221SonicWall SMA100 SSL-VPN management interface OS command injectionThe SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds adminis…KEVEPSS 76%analysed6.5CVE-2021-20035SonicWall SMA100 management interface OS command injectionThe SMA100 management interface fails to neutralize special elements, letting a remote authenticated attacker inject arbitrary commands that run as t…KEVEPSS 4.2%analysed9.8CVE-2022-22273Sonicwall sma 200 firmware os command injection vulnerabilityImproper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…EPSS 1.9%9.8CVE-2021-20042Sonicwall sma 200 firmware vulnerabilityAn unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi…EPSS 2.6%9.8CVE-2021-20045Sonicwall sma 200 firmware classic buffer overflow vulnerabilityA buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execut…EPSS 25%

Source: NIST National Vulnerability Database (record CVE-2021-20028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.