CVE-2023-44221: SonicWall SMA100 Appliances OS Command Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2025-05-01. EPSS: 76.3% chance of exploitation in the next 30 days.

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

Affected products

  • SonicWall SMA 200 Firmware: up to and including 10.2.1.9-57sv
  • SonicWall SMA 210 Firmware: up to and including 10.2.1.9-57sv
  • SonicWall SMA 400 Firmware: up to and including 10.2.1.9-57sv
  • SonicWall SMA 410 Firmware: up to and including 10.2.1.9-57sv
  • SonicWall SMA 500v Firmware: up to and including 10.2.1.9-57sv

Published 2023-12-05. Last modified 2026-06-17.