High severity8.8NVD Advisory· Published May 27, 2021· Updated Jun 17, 2026
CVE-2021-20026
CVE-2021-20026
Description
A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.
Affected products
5cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:on-premises:*:*:*+ 2 more
- cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:on-premises:*:*:*range: <2.2.0
- cpe:2.3:a:sonicwall:network_security_manager:2.2.0:-:*:*:on-premises:*:*:*
- cpe:2.3:a:sonicwall:network_security_manager:2.2.0:r10:*:*:on-premises:*:*:*
- Range: <=2.2.0-R10
- SonicWall/SonicWall NSM On-Premv5Range: NSM On-Prem 2.2.0-R10 and earlier
Patches
Vulnerability mechanics
References
1- psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0014nvdVendor Advisory
News mentions
0No linked articles in our index yet.