PT-2025-20281 · Sonicwall · Sonicwall Sma100

Ryan Emmons

·

Published

2025-05-07

·

Updated

2025-08-22

·

CVE-2025-32819

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SonicWall SMA 100 versions (affected versions not specified)
Description A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file, potentially resulting in a reboot to factory default settings. The issue also allows low-privileged users to escalate to admin/root and execute remote code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

RCE

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

BDU:2025-05377
CVE-2025-32819

Affected Products

Sonicwall Sma100