CVE-2020-5146: SonicWall SMA 100 Firmware

High severity, CVSS 7.2. EPSS: 1.9% chance of exploitation in the next 30 days.

A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.

Affected products

  • SonicWall SMA 100 Firmware: up to and including 10.2.0.2-20sv

Published 2021-01-09. Last modified 2026-06-17.