Critical severity9.8CISA KEVNVD Advisory· Published Feb 4, 2021· Updated Aug 12, 2026
CVE-2021-20016
CVE-2021-20016
Description
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- cpe:2.3:o:sonicwall:sma_100_firmware:*:*:*:*:*:*:*:*Range: >=10.0.0.0,<10.2.0.5-d-29sv
- cpe:2.3:o:sonicwall:sma_200_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma_210_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma_400_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sma_410_firmware:-:*:*:*:*:*:*:*
- SonicWall/SonicWall SMA100v5Range: SMA100 build version 10.x
Patches
Vulnerability mechanics
References
2- psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001nvdMitigationVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildTenable Blog · Jul 15, 2026