CVE-2019-7481 is a critical SQL injection vulnerability in SonicWall SMA100 firmware versions 9.0.0.3 and earlier, allowing unauthenticated attackers to gain read-only access to unauthorized resources. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, this flaw allows remote attackers to compromise confidentiality without user interaction. The vulnerability is actively exploited, notably by ransomware groups like Lockbit 2.0 and HelloKitty, and has garnered significant community attention with public Nuclei templates and numerous media reports confirming its use in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.0.0.4CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_100_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.