Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2021-11-03 — agencies required to remediate by 2021-11-17 · Ransomware

CVE-2021-20016

CRITICAL

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related…

Published
Feb 4, 2021
Updated
Oct 31, 2025
Affected
0 pkgs
Patched
None yet
Exploits
2 known

Description

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

Affected Products

6 products · 6 configurations
OS
sma 100 firmwaresonicwall
≥ 10.0.0.0 && < 10.2.0.5-d-29sv
range
OS
sma 200 firmwaresonicwall
all
OS
sma 210 firmwaresonicwall
all
OS
sma 400 firmwaresonicwall
all
OS
sma 410 firmwaresonicwall
all
Application
sma 500vsonicwall
all
Exploits & PoCs
2

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Frequently Asked Questions

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
O3 Security · Impact-Aware SCA

Is CVE-2021-20016 in your stack?

O3 detects CVE-2021-20016 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.