📦 Sma 410 Firmware

by Sonicwall

🔍 What is Sma 410 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-40599

CRITICAL CVSS 9.1 Jul 23, 2025

An authenticated arbitrary file upload vulnerability in SMA 100 series web management interface allows attackers with administrative privileges to upload malicious files. This could lead to remote cod...

CVE-2022-22273

CRITICAL CVSS 9.8 Mar 17, 2022

This CVE allows attackers to execute arbitrary operating system commands on vulnerable SonicWall Secure Remote Access (SRA) and Secure Mobile Access (SMA) appliances through improper input sanitizatio...

CVE-2021-20042

CRITICAL CVSS 9.8 Dec 8, 2021

CVE-2021-20042 allows unauthenticated remote attackers to use SonicWall SMA 100 series appliances as unintended proxies to bypass firewall rules. This affects SMA 200, 210, 400, 410, and 500v applianc...

CVE-2021-20045

CRITICAL CVSS 9.8 Dec 8, 2021

A buffer overflow vulnerability in SonicWall SMA appliances allows remote unauthenticated attackers to execute arbitrary code as the 'nobody' user. This affects SMA 200, 210, 400, 410, and 500v applia...

CVE-2021-20038

CRITICAL CVSS 9.8 Dec 8, 2021

A stack-based buffer overflow vulnerability in SonicWall SMA 100 series appliances' Apache httpd mod_cgi module allows remote unauthenticated attackers to execute arbitrary code as the 'nobody' user. ...

CVE-2021-20034

CRITICAL CVSS 9.1 Sep 27, 2021

CVE-2021-20034 is an improper access control vulnerability in SonicWall SMA100 appliances that allows unauthenticated attackers to bypass path traversal checks and delete arbitrary files. This could l...

CVE-2021-20028

CRITICAL CVSS 9.8 Aug 4, 2021

This CVE describes a critical SQL injection vulnerability in SonicWall Secure Remote Access (SRA) appliances. Attackers can exploit this to execute arbitrary SQL commands, potentially leading to data ...

CVE-2025-40596

HIGH CVSS 7.3 Jul 23, 2025

A stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attackers to cause denial of service or potentially execute arbitrary code. This affects o...

CVE-2025-32819

HIGH CVSS 8.8 May 7, 2025

This vulnerability allows authenticated SSLVPN users on SMA100 devices to bypass path traversal protections and delete arbitrary files. Attackers could force a factory reset, causing service disruptio...

CVE-2025-32821

HIGH CVSS 7.2 May 7, 2025

A command injection vulnerability in SMA100 SSL-VPN appliances allows authenticated administrators to execute arbitrary shell commands by manipulating file upload parameters. This affects organization...

CVE-2024-53703

HIGH CVSS 8.1 Dec 5, 2024

A stack-based buffer overflow vulnerability in SonicWall SMA100 SSLVPN firmware's mod_httprp library allows remote attackers to potentially execute arbitrary code. This affects SMA100 appliances runni...

CVE-2024-45318

HIGH CVSS 8.1 Dec 5, 2024

A stack-based buffer overflow vulnerability in SonicWall SMA100 SSLVPN web management interface allows remote attackers to execute arbitrary code on affected devices. This affects organizations using ...

CVE-2023-5970

HIGH CVSS 8.8 Dec 5, 2023

This vulnerability allows a remote authenticated attacker to bypass multi-factor authentication (MFA) on SonicWall SMA100 SSL-VPN virtual office portals by creating duplicate external domain users usi...

CVE-2021-20049

HIGH CVSS 7.5 Dec 23, 2021

CVE-2021-20049 is a username enumeration vulnerability in SonicWall SMA100's password change API that allows unauthenticated attackers to determine valid usernames by analyzing server responses. This ...

CVE-2021-20044

HIGH CVSS 8.8 Dec 8, 2021

A post-authentication remote command injection vulnerability in SonicWall SMA100 appliances allows authenticated attackers to execute arbitrary operating system commands on affected devices. This affe...

CVE-2021-20040

HIGH CVSS 7.5 Dec 8, 2021

A relative path traversal vulnerability in SonicWall SMA appliances allows unauthenticated remote attackers to upload arbitrary files as a low-privileged 'nobody' user. This affects SMA 200, 210, 400,...

CVE-2025-40603

MEDIUM CVSS 4.5 Oct 31, 2025

A vulnerability in SonicWall SMA100 Series appliances may expose partial user credential data in log files under certain conditions. This allows remote authenticated administrators to potentially view...

CVE-2025-40598

MEDIUM CVSS 6.1 Jul 23, 2025

A reflected cross-site scripting (XSS) vulnerability in the SMA100 series web interface allows remote unauthenticated attackers to inject and execute arbitrary JavaScript code in victims' browsers. Th...

CVE-2024-53702

MEDIUM CVSS 5.3 Dec 5, 2024

This vulnerability in SonicWall SMA100 SSLVPN devices uses a weak random number generator for backup codes, allowing attackers to potentially predict these codes. This affects organizations using vuln...