← Vulnerability feed

Vulnerability record · CVE-2021-20039 · published 8 December 2021

CVE-2021-20039: SonicWall SMA management interface command injection via viewcert

Sonicwall · Sma 200 Firmware

The SMA100 management interface endpoint /cgi-bin/viewcert fails to neutralize special elements in POST input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the appliance as the low-privileged 'nobody' user. The flaw affects SMA 200, 210, 400, 410 and 500v appliances and is rated CVSS 8.8 (HIGH).

8.8 CVSS 3.1 High EPSS 79% · top 0.4% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with a very high EPSS score and a public exploit reference make this a high-priority authenticated command injection, though it is not in KEV and requires valid credentials.

What it is

The SMA100 management interface endpoint /cgi-bin/viewcert fails to neutralize special elements in POST input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the appliance as the low-privileged 'nobody' user. The flaw affects SMA 200, 210, 400, 410 and 500v appliances and is rated CVSS 8.8 (HIGH).

Impact

An authenticated attacker gains arbitrary command execution on the SMA appliance under the 'nobody' account, with high confidentiality, integrity and availability impact per the CVSS vector. This can expose configuration and credential material and allow further host-level actions within the limits of that account.

Attack surface

Reached over the network through the SMA100 management interface via an HTTP POST to /cgi-bin/viewcert. Authentication is required (PR:L) and no user interaction is needed (UI:N); the vector is AV:N/AC:L.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.78746, 99.57th percentile) and a public Packet Storm exploit reference exists, indicating mature public exploitation tooling. No ransomware group usage is documented in the record.

What to do

  • Apply the vendor fix from SonicWall PSIRT advisory SNWLID-2021-0026 for the affected SMA 200, 210, 400, 410 and 500v appliances.
  • Restrict management interface access to trusted networks or an administrative VLAN; do not expose the SMA management UI to the internet.
  • Enforce least privilege and strong unique credentials for SMA administrative accounts, and audit accounts that can reach /cgi-bin/viewcert.
  • Monitor and alert on unexpected outbound or process activity originating from the SMA appliance.
  • Review SMA logs for anomalous POST requests to /cgi-bin/viewcert and for command execution under the 'nobody' account.

Detection

  • Search web/proxy and SMA logs for POST requests to /cgi-bin/viewcert with shell metacharacters or unexpected parameters.
  • Alert on processes or child shells spawned by the SMA web service running as 'nobody'.
  • Monitor for unusual outbound connections or file writes from the SMA appliance after management interface activity.
  • Correlate authenticated management sessions with subsequent command execution or configuration changes on the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20038SonicWall SMA 100 appliances stack buffer overflow in mod_cgiA stack-based buffer overflow in the Apache httpd mod_cgi module of SonicWall SMA 100 series appliances lets a remote unauthenticated attacker overwr…KEVEPSS 100%analysed9.8CVE-2021-20028SonicWall SRA appliances SQL injection in end-of-life firmwareSonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL in…KEVEPSS 30%analysed9.8CVE-2021-20016SonicWall SMA100 SSLVPN SQL injection allows unauthenticated accessSonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to …KEVEPSS 40%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed7.2CVE-2023-44221SonicWall SMA100 SSL-VPN management interface OS command injectionThe SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds adminis…KEVEPSS 76%analysed6.5CVE-2021-20035SonicWall SMA100 management interface OS command injectionThe SMA100 management interface fails to neutralize special elements, letting a remote authenticated attacker inject arbitrary commands that run as t…KEVEPSS 4.2%analysed9.8CVE-2022-22273Sonicwall sma 200 firmware os command injection vulnerabilityImproper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…EPSS 1.9%9.8CVE-2021-20042Sonicwall sma 200 firmware vulnerabilityAn unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2021-20039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.