PT-2025-30578 · Unknown · Sma 100 Series

Dawid Skomski

·

Published

2025-07-23

·

Updated

2025-08-06

·

CVE-2025-40599

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicWall SMA 100 Series versions 210, 410, and 500v SonicWall SMA 100 Series (affected versions not specified)
Description A critical authenticated arbitrary file upload vulnerability exists in the SonicWall SMA 100 series web management interface. This flaw allows a remote attacker with administrative privileges to upload arbitrary files to the system, potentially leading to remote code execution (RCE). Multiple threat actors, including UNC6148 and those associated with the Akira, Fog, Babuk, Overstep, Abyss locker, and Vsociety malware, have been observed exploiting this vulnerability. The Overstep backdoor has been actively deployed on compromised devices. Numerous ransomware groups have targeted SonicWall appliances, and this vulnerability has been actively exploited in ongoing campaigns. Compromised privileged accounts have been used for lateral movement and data exfiltration.
Recommendations SonicWall SMA 100 Series versions 210, 410, and 500v: Update to a fixed version. SonicWall SMA 100 Series (affected versions not specified): Update to a fixed version.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-10717
CVE-2025-40599

Affected Products

Sma 100 Series