Vulnerability record · CVE-2021-20028 · published 4 August 2021
CVE-2021-20028: SonicWall SRA appliances SQL injection in end-of-life firmware
Sonicwall · Sma 210 Firmware
SonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL injection. The affected products are end-of-life, so no fix path exists and exposure persists wherever these appliances remain deployed.
Description
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote SQL injection on internet-facing remote access appliances, listed in KEV with known ransomware use and no patch available for end-of-life hardware.
What it is
SonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL injection. The affected products are end-of-life, so no fix path exists and exposure persists wherever these appliances remain deployed.
Impact
An unauthenticated remote attacker can inject SQL to read or alter backend data and potentially execute commands in the appliance context, compromising the remote access gateway itself.
Attack surface
Reachable over the network via the appliance's web interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Listed in CISA KEV since 2022-03-28 with known ransomware campaign use, and EPSS shows a 30-day probability of about 30 percent (98th percentile), indicating active exploitation.
What to do
- Disconnect or retire any end-of-life SRA appliance still in use, as CISA and the vendor require; there is no supported patch for these models.
- If immediate removal is impossible, isolate the appliance from the internet and restrict management and user access to trusted networks only.
- Migrate remote access to a supported SonicWall SMA or other maintained VPN/SSL-VPN platform.
- Audit for signs of prior compromise before decommissioning, since the device may already be backdoored.
Detection
- Search web or WAF logs for SQL metacharacters and injection patterns in requests to SRA login and portal endpoints.
- Monitor appliance and adjacent systems for unexpected outbound connections, new accounts, or configuration changes.
- Hunt for known post-exploitation artifacts on the appliance and internal hosts that communicated with it.
- Inventory the network for SRA 8.x and 9.0.0.9-26sv or earlier firmware to confirm remaining exposure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20028 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 18 April 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0017 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0017 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20028 | US Government Resource |
Track CVE-2021-20028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.