Impact
An authenticated command injection flaw in the Command‑Line Interface of SonicWall GMS versions 9.5.1 and earlier lets a low‑privileged local user run arbitrary system commands with root privileges. The weakness, classified as CWE‑94, permits attackers to inject shell commands that are executed in the context of the operating system, effectively bypassing normal access controls.
Affected Systems
Vulnerable products are SonicWall GMS command‑line interface software release 9.5.1 (Build 9510.1044) and all earlier releases. The flaw applies to any installation that allows local users to authenticate to the CLI.
Risk and Exploitability
The CVSS base score of 6.3 indicates a moderate level of severity, but the EPSS score of 1% suggests that exploitation is not yet highly common. The vulnerability is not listed in CISA’s KEV catalog. Because the attack requires local authenticated access, it poses a risk primarily to individuals with physical or console access, yet compromised local users can elevate to root, potentially enabling full system takeover. The likelihood of exploitation remains limited to environments where local CLI access is available but it should be considered a high‑impact risk once the flaw is discovered by a threat actor.
OpenCVE Enrichment