Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      HBAR Shorts Face $5 Million Risk if Price Breaks Key Level

      February 10, 2026

      Ethereum Holds $2,000 Support — Accumulation Keeps Recovery Hopes Alive

      February 10, 2026

      Miami Mansion Listed for 700 BTC as California Billionaire Tax Sparks Relocations

      February 10, 2026

      Solana Drops to 2-Year Lows — History Suggests a Bounce Toward $100 is Incoming

      February 10, 2026

      Bitget Cuts Stock Perps Fees to Zero for Makers Ahead of Earnings Season, Expanding Access Across Markets

      February 10, 2026
    • Technology

      Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

      February 10, 2026

      Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

      February 10, 2026

      New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

      February 10, 2026

      TikTok-Linked AI Video Tool Debuts With a Catch for the US

      February 10, 2026

      24 Best Last-Minute Valentine’s Day Gifts in 2025: Physical and Digital Options for Everyone

      February 10, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»SonicWall SMA VPN devices targeted in attacks since January
    Technology

    SonicWall SMA VPN devices targeted in attacks since January

    TechAiVerseBy TechAiVerseApril 20, 2025No Comments3 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    SonicWall SMA VPN devices targeted in attacks since January
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    SonicWall SMA VPN devices targeted in attacks since January

    A remote code execution vulnerability affecting SonicWall Secure Mobile Access (SMA) appliances has been under active exploitation since at least January 2025, according to cybersecurity company Arctic Wolf.

    This security flaw (CVE-2021-20035) impacts SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v devices and was patched almost four years ago, in September 2021, when SonicWall said it could only be exploited to take down vulnerable appliances in denial-of-service (DoS) attacks.

    However, the company updated the four-year-old security advisory on Monday to flag the security bug as exploited in attacks, expand the impact to include remote code execution, and upgrade the CVSS severity score from medium to high severity.

    “This vulnerability is believed to be actively exploited in the wild. As a precautionary measure, SonicWall PSIRT has updated the summary and revised the CVSS score to 7.2,” SonicWall said.

    Successful exploitation can allow remote threat actors with low privileges to exploit an “improper neutralization of special elements in the SMA100 management interface” to inject arbitrary commands as a ‘nobody’ user and execute arbitrary code in low-complexity attacks.

    CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog, confirming it’s now being abused in the wild and ordering Federal Civilian Executive Branch (FCEB) agencies to secure their networks against ongoing attacks until May 7th.

    Product Platform Impacted Version Fixed version
    SMA 100 Series • SMA 200
    • SMA 210
    • SMA 400
    • SMA 410
    • SMA 500v (ESX, KVM, AWS, Azure)
    10.2.1.0-17sv and earlier 10.2.1.1-19sv and higher
    10.2.0.7-34sv and earlier 10.2.0.8-37sv and higher
    9.0.0.10-28sv and earlier 9.0.0.11-31sv and higher

    Actively exploited since January

    Days after SonicWall tagged the security bug as exploited in the wild without sharing when the attacks started, cybersecurity company Arctic Wolf reported that threat actors used CVE-2021-20035 exploits in attacks as early as January 2025.

    In this campaign, the attackers have also used a local super admin account with a “password” default password to target SMA 100 appliances with the management interface exposed online.

    “Arctic Wolf has identified an ongoing VPN credential access campaign targeting SMA 100 series appliances, with a starting timeframe as early as January 2025, extending into April 2025,” the cybersecurity firm said.

    “One noteworthy aspect of the campaign was the use of a local super admin account (admin@LocalDomain) on these appliances, which has an insecure default password of password.”

    To block CVE-2021-20035 attacks targeting their SonicWall appliances, Arctic Wolf advised network defenders to limit VPN access to the minimum necessary accounts, deactivate unneeded accounts, enable multi-factor authentication for all accounts, and reset passwords for all local accounts on SonicWall SMA firewalls.

    In February, SonicWall also urged customers in January to patch a critical vulnerability affecting SMA1000 secure access gateways following reports that it had already been exploited in zero-day attacks and, one month later, warned of an actively exploited authentication bypass flaw in Gen 6 and Gen 7 firewalls that can let hackers hijack VPN sessions.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleChinese hackers target Russian govt with upgraded RAT malware
    Next Article Critical Erlang/OTP SSH RCE bug now has public exploits, patch now
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    February 10, 2026

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    February 10, 2026

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    February 10, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025663 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025250 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025150 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Technology February 10, 2026

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and…

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    TikTok-Linked AI Video Tool Debuts With a Catch for the US

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    February 10, 20262 Views

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    February 10, 20262 Views

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    February 10, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.