• News/
  • https://www.bleepingcomputer.com/news/security/sonicwall-sma-vpn-devices-targeted-in-attacks-since-january/

SonicWall SMA VPN devices targeted in attacks since January

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 18, 2025
·
Updated

A remote code execution vulnerability affecting SonicWall Secure Mobile Access (SMA) appliances has been under active exploitation since at least January 2025, according to cybersecurity company Arctic Wolf. This security flaw (CVE-2021-20035) impacts SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v devices and was patched almost four years ago, in September 2021, when SonicWall said it could only be exploited to take down vulnerable appliances in denial-of-service (DoS) attacks. However, the company updated the four-year-old security advisory on Monday to flag the security bug as exploited in attacks, expand the impact to include remote code execution, and upgrade the CVSS severity score from medium to high severity. "This vulnerability is believed to be actively exploited in the wild. As a precautionary measure, SonicWall PSIRT has updated the summary and revised the CVSS score to 7.2," SonicWall said. Successful exploitation can allow remote threat actors with low privileges to exploit an "improper neutralization of special elements in the SMA100 management interface" to inject arbitrary commands as a 'nobody' user and execute arbitrary code in low-complexity attacks. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog, confirming it's now being abused in the wild and ordering Federal Civilian Executive Branch (FCEB) agencies to secure their networks against ongoing attacks until May 7th. Days after SonicWall tagged the security bug as exp...

Read full article

Affected Software

10 affected components
SonicWall Secure Mobile Access=200
SonicWall Secure Mobile Access=210
SonicWall Secure Mobile Access=400
SonicWall Secure Mobile Access=410
SonicWall Secure Mobile Access=500v
SonicWall Secure Mobile Access=200
SonicWall Secure Mobile Access=210
SonicWall Secure Mobile Access=400
SonicWall Secure Mobile Access=410
SonicWall Secure Mobile Access=500v

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the ongoing exploitation of a remote code execution vulnerability in SonicWall Secure Mobile Access (SMA) appliances.

2

What security implications are discussed in the article?

The article highlights that the identified vulnerability has been under active exploitation since January 2025, posing significant risks to affected devices.

3

What specific products are affected by the vulnerability?

The affected products include SonicWall Secure Mobile Access appliances, particularly versions 200, 210, 400, 410, and 500v.

4

Who identified the vulnerability and its exploitation?

The cybersecurity firm Arctic Wolf reported the vulnerability and its active exploitation.

5

What should users of SonicWall SMA devices do in response to this vulnerability?

Users are advised to take immediate action to secure their devices and apply any available security patches from SonicWall.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203