Known vulnerabilities in NetExtender for Linux

Vendor: SonicWall
Software CPE: cpe:2.3:a:sonicwall:netextender_for_linux:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting NetExtender for Linux NetExtender for Linux is affected by 3 known vulnerabilities: 1 critical, 1 high, 1 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145834 - Path Traversal: \'\\..\\filename\'
CVE-2026-66152
CWE-29 High
No
No
10.3.6-39 26.08.2026 SB2026082682
#VU145835 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-66153
CWE-59 Low
No
No
10.3.6-39 26.08.2026 SB2026082682
#VU49936 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2021-20016
CWE-89 Critical
No
Exploited
- 24.01.2021 SB2021012401