CVE-2021-20028

CVE-2021-20028

Vendor Sonicwall
Product SonicWall SRA/SMA100
Weakness CWE-89 · SQLi
KEV Status Known Exploited
Ransomware Used in campaigns
Published August 4, 2021
Last update October 21, 2025

CVSS base score

What the vulnerability does

01Description

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

CISA mandated remediation

02CISA Required Action

The impacted product is end-of-life and should be disconnected if still in use.

Key dates

03Disclosure timeline

August 4, 2021 CVE published
October 21, 2025 Record updated