CRITICAL🇵🇱 Wersja polska

CVE-2025-40599

CVSS 9.1v3.1pub. 2025-07-23upd. 2025-11-06

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) consists of the lack of proper verification of uploaded files in the web interface of the administrative panel. A remote attacker possessing an administrator account can upload any file — including an executable file or script — directly to the device's file system. After placing a malicious file on the device, it is possible to trigger arbitrary code execution in the context of the device's operating system.

Impact

An attacker can gain the ability to execute code remotely (RCE) on the SMA device, which may consequently lead to complete takeover of the device, data leakage, and system integrity violation.

Mitigation & patch

Patches available from the manufacturer should be applied according to references published at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014. Additionally, it is recommended to restrict access to the administrative interface exclusively to trusted IP addresses and implement the principle of least privilege for administrative accounts.

Who is affected

SonicWall SMA 210, SMA 410, SMA 500V and their corresponding firmware versions — specific versions indicated in manufacturer references (SNWLID-2025-0014).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Sonicwall Sma 210

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 210 Firmware

    OS
    Sonicwall
    < 10.2.2.1-90sv
  • Sonicwall Sma 410

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 410 Firmware

    OS
    Sonicwall
    < 10.2.2.1-90sv
  • Sonicwall Sma 500v

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 500v Firmware

    OS
    Sonicwall
    < 10.2.2.1-90sv
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-38475CRITICAL9.1⚠ KEVPL ✓same product

Apache HTTP Server mod_rewrite — ujawnienie kodu i RCE poprzez błędne escapowanie

CVE-2021-20038CRITICAL9.8⚠ KEVPL ✓same product

Stack-based buffer overflow w SonicWall SMA 100 — zdalny RCE bez uwierzytelnienia

CVE-2021-20028CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w urządzeniach SonicWall SRA/SMA — zdalne przejęcie kontroli

CVE-2021-20016CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w SonicWall SMA100 SSLVPN — dostęp do danych bez uwierzytelnienia

CVE-2022-22273CRITICAL9.8PL ✓same product

OS Command Injection w SonicWall SRA i SMA 100 — zdalne wykonanie poleceń