Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/chriszubiaga/cvedetails-scraper
- https://github.com/packetinside/CISA_BOT
- https://github.com/ums91/CISA_BOT
- https://github.com/watchtowrlabs/watchTowr-vs-SonicWall-PreAuth-RCE-Chain