Vulnerability record · CVE-2021-20039 · published 8 December 2021
CVE-2021-20039: SonicWall SMA management interface command injection via viewcert
Sonicwall · Sma 200 Firmware
The SMA100 management interface endpoint /cgi-bin/viewcert fails to neutralize special elements in POST input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the appliance as the low-privileged 'nobody' user. The flaw affects SMA 200, 210, 400, 410 and 500v appliances and is rated CVSS 8.8 (HIGH).
Description
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with a very high EPSS score and a public exploit reference make this a high-priority authenticated command injection, though it is not in KEV and requires valid credentials.
What it is
The SMA100 management interface endpoint /cgi-bin/viewcert fails to neutralize special elements in POST input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the appliance as the low-privileged 'nobody' user. The flaw affects SMA 200, 210, 400, 410 and 500v appliances and is rated CVSS 8.8 (HIGH).
Impact
An authenticated attacker gains arbitrary command execution on the SMA appliance under the 'nobody' account, with high confidentiality, integrity and availability impact per the CVSS vector. This can expose configuration and credential material and allow further host-level actions within the limits of that account.
Attack surface
Reached over the network through the SMA100 management interface via an HTTP POST to /cgi-bin/viewcert. Authentication is required (PR:L) and no user interaction is needed (UI:N); the vector is AV:N/AC:L.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.78746, 99.57th percentile) and a public Packet Storm exploit reference exists, indicating mature public exploitation tooling. No ransomware group usage is documented in the record.
What to do
- Apply the vendor fix from SonicWall PSIRT advisory SNWLID-2021-0026 for the affected SMA 200, 210, 400, 410 and 500v appliances.
- Restrict management interface access to trusted networks or an administrative VLAN; do not expose the SMA management UI to the internet.
- Enforce least privilege and strong unique credentials for SMA administrative accounts, and audit accounts that can reach /cgi-bin/viewcert.
- Monitor and alert on unexpected outbound or process activity originating from the SMA appliance.
- Review SMA logs for anomalous POST requests to /cgi-bin/viewcert and for command execution under the 'nobody' account.
Detection
- Search web/proxy and SMA logs for POST requests to /cgi-bin/viewcert with shell metacharacters or unexpected parameters.
- Alert on processes or child shells spawned by the SMA web service running as 'nobody'.
- Monitor for unusual outbound connections or file writes from the SMA appliance after management interface activity.
- Correlate authenticated management sessions with subsequent command execution or configuration changes on the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165563/SonicWall-SMA-100-Series-Authenticated-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0026 | Vendor Advisory |
| http://packetstormsecurity.com/files/165563/SonicWall-SMA-100-Series-Authenticated-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0026 | Vendor Advisory |
| https://attackerkb.com/topics/9szJhq46lw/cve-2021-20039/rapid7-analysis |
Track CVE-2021-20039 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.