Web Scanning SonicWall for CVE-2021-20016 – Update

Date:

Share post:

I published on the 29 Apr 2025 a diary [1] on scanning activity looking for SonicWall and since this publication this activity has grown 10-fold. Over the past 14 days, several BACS students have reported activity related to SonicWall scans all related for the same 2 URLs [4][5] previously mentioned in my last diary. My own DShield sensor was probed by 25 separate IPs during those last 14 days. The three most active IPs were all from the same subnet – 141.98.80.0/24

Activity by URL

Indicator

185.193.88.229

185.193.88.178

185.193.88.223

141.98.80.125

141.98.80.126

141.98.80.118

92.63.196.249

92.63.196.152

80.82.65.127

45.146.130.12

[1] https://isc.sans.edu/diary/Web+Scanning+Sonicwall+for+CVE202120016/31906/

[2] https://es-la.tenable.com/blog/cve-2021-20016-zero-day-vulnerability-in-sonicwall-secure-mobile-access-sma-exploited

[3] https://cow-prod-www-v3.azurewebsites.net/publications/security-advisories/2021-006/pdf

[4] https://isc.sans.edu/weblogs/urlhistory.html?url=L19fYXBpX18vdjEvY29uZmlnL2RvbWFpbnM=

[5] https://isc.sans.edu/weblogs/urlhistory.html?url=L19fYXBpX18vdjEvbG9nb24=

[6] https://www.sans.edu/cyber-security-programs/bachelors-degree/

———–

Guy Bruneau IPSS Inc.

My GitHub Page

Twitter: GuyBruneau

gbruneau at isc dot sans dot edu



Source link

spot_img

Related articles

Bulletproof Host Stark Industries Evades EU Sanctions – Krebs on Security

In May 2025, the European Union levied financial sanctions on the owners of Stark Industries Solutions Ltd., a bulletproof...

MSI Afterburner developer adding ‘triple channel voltage’ support for future MSI RTX 50 graphics cards

MSI Afterburner's sole developer, Alexey Nicolaychuk, is working on a new update for the app that will expand...

AMD FSR 4 now available in over 85 games

Delivering incredible graphics without compromising performance remains a priority for gamers and developers alike. Enter AMD FidelityFXâ„¢...