PT-2025-30578 · Unknown · Sma 100 Series

Dawid Skomski

·

Publicado

2025-07-23

·

Atualizado

2025-08-06

·

CVE-2025-40599

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicWall SMA 100 Series versions 210, 410, and 500v SonicWall SMA 100 Series (affected versions not specified)
Description A critical authenticated arbitrary file upload vulnerability exists in the SonicWall SMA 100 series web management interface. This flaw allows a remote attacker with administrative privileges to upload arbitrary files to the system, potentially leading to remote code execution (RCE). Multiple threat actors, including UNC6148 and those associated with the Akira, Fog, Babuk, Overstep, Abyss locker, and Vsociety malware, have been observed exploiting this vulnerability. The Overstep backdoor has been actively deployed on compromised devices. Numerous ransomware groups have targeted SonicWall appliances, and this vulnerability has been actively exploited in ongoing campaigns. Compromised privileged accounts have been used for lateral movement and data exfiltration.
Recommendations SonicWall SMA 100 Series versions 210, 410, and 500v: Update to a fixed version. SonicWall SMA 100 Series (affected versions not specified): Update to a fixed version.

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-10717
CVE-2025-40599

Produtos afetados

Sma 100 Series