Tz350w
Vendor:
First CVE: Jun 14, 2021 · Active for 5 years
14
Total CVEs
More Total CVEs than 88% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
7.1%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tz350w over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2021
5 years ago
Most Recent CVE
Apr 29, 2026
87 days ago
CVE Severity & Scoring
Tz350w14 CVEs
36%
57%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (78.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (21.4%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low3 (21.4%)
High1 (7.1%)
None10 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-40766CRITICAL An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditi | Aug 23, 2024 | 9.8 | 80 | YES | NO |
CVE-2021-20031MEDIUM A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains. | Oct 12, 2021 | 6.1 | 46 | NO | YES |
CVE-2026-0204HIGH A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. | Apr 29, 2026 | 8.0 | 35 | NO | NO |
CVE-2026-0205MEDIUM A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. | Apr 29, 2026 | 6.8 | 30 | NO | NO |
CVE-2021-20048HIGH A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code | Jan 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-20046HIGH A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in | Jan 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-0206MEDIUM A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. | Apr 29, 2026 | 4.9 | 25 | NO | NO |
CVE-2022-47522HIGH The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, se | Apr 15, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-1101HIGH SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes. | Mar 2, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-22275HIGH Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service | Apr 27, 2022 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
1 CVE
7.1% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.1% of CVEs· 97th percentile
ExploitDB
1 CVE
7.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Tz350w
Top CWEs
Versions
No cataloged versions.