
SonicWall「Virtual Office」SSL-VPN製品には、ShellShockに対して脆弱な非常に古いバージョンのBashが同梱されており、そのため/cgi-bin/jarrewrite.sh URLを介して、認証なしのリモートコード実行(「nobody」ユーザーとして)に対して脆弱です。

https://github.com/darrenmartyn/visualdoor
https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit