An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.
The vulnerability classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) consists of the lack of proper verification of uploaded files in the web interface of the administrative panel. A remote attacker possessing an administrator account can upload any file — including an executable file or script — directly to the device's file system. After placing a malicious file on the device, it is possible to trigger arbitrary code execution in the context of the device's operating system.
An attacker can gain the ability to execute code remotely (RCE) on the SMA device, which may consequently lead to complete takeover of the device, data leakage, and system integrity violation.
Patches available from the manufacturer should be applied according to references published at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014. Additionally, it is recommended to restrict access to the administrative interface exclusively to trusted IP addresses and implement the principle of least privilege for administrative accounts.
SonicWall SMA 210, SMA 410, SMA 500V and their corresponding firmware versions — specific versions indicated in manufacturer references (SNWLID-2025-0014).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSonicwall Sma 210
HWSonicwallall versionsSonicwall Sma 210 Firmware
OSSonicwall< 10.2.2.1-90svSonicwall Sma 410
HWSonicwallall versionsSonicwall Sma 410 Firmware
OSSonicwall< 10.2.2.1-90svSonicwall Sma 500v
HWSonicwallall versionsSonicwall Sma 500v Firmware
OSSonicwall< 10.2.2.1-90sv
Related vulnerabilities
Apache HTTP Server mod_rewrite — ujawnienie kodu i RCE poprzez błędne escapowanie
Stack-based buffer overflow w SonicWall SMA 100 — zdalny RCE bez uwierzytelnienia
SQL Injection w urządzeniach SonicWall SRA/SMA — zdalne przejęcie kontroli
SQL Injection w SonicWall SMA100 SSLVPN — dostęp do danych bez uwierzytelnienia
OS Command Injection w SonicWall SRA i SMA 100 — zdalne wykonanie poleceń