What it is
CVE-2021-20039 is a vulnerability affecting SonicWall SonicWall SMA100. Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated...
Vulnerability report
SonicWall SMA100
SonicWall / SonicWall SMA100 · 9.0.0.11-31sv and earlier
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2021-20039 is a vulnerability affecting SonicWall SonicWall SMA100. Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated...
Is it exploited?
No. KEV Intelligence has not recorded active exploitation signals yet.
Who is affected?
SonicWall / SonicWall SMA100 9.0.0.11-31sv and earlier.
What should we do?
Track for updates. Assess relevance to your asset inventory and enrichment workflows.
Overview
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user.
This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Exploitation evidence
Catalogues and sources that list this CVE as a known exploited vulnerability, when available.
No exploitation evidence rows are recorded for this CVE yet.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
Metasploit template detected 28 Apr 2025.
View Metasploit template (opens in new tab)No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/sonicwall_cve_2021_20039.rb | 28 Apr 2025 |
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
—
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:C/I:C/A:C
These PoCs are unverified and could contain malware. Use at your own risk.
Timeline
Exploit module available
Public proof-of-concept code published
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2021-20039
Free JSON includes basic KEV fields{
"cve_id": "CVE-2021-20039",
"confidence": null,
"cvss_score": 8.8,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": false,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}