HomeCyber SecuritySonicWall Patches 3 Flaws in SMA 100 Units Permitting Attackers to Run...

SonicWall Patches 3 Flaws in SMA 100 Units Permitting Attackers to Run Code as Root


Could 08, 2025Ravie LakshmananCommunity Safety / Vulnerability

SonicWall Patches 3 Flaws in SMA 100 Units Permitting Attackers to Run Code as Root

SonicWall has launched patches to handle three safety flaws affecting SMA 100 Safe Cell Entry (SMA) home equipment that might be normal to lead to distant code execution.

The vulnerabilities are listed beneath –

  • CVE-2025-32819 (CVSS rating: 8.8) – A vulnerability in SMA100 permits a distant authenticated attacker with SSL-VPN consumer privileges to bypass the trail traversal checks and delete an arbitrary file doubtlessly leading to a reboot to manufacturing unit default settings.
  • CVE-2025-32820 (CVSS rating: 8.3) – A vulnerability in SMA100 permits a distant authenticated attacker with SSL-VPN consumer privileges can inject a path traversal sequence to make any listing on the SMA equipment writable
  • CVE-2025-32821 (CVSS rating: 6.7) – A vulnerability in SMA100 permits a distant authenticated attacker with SSL-VPN admin privileges can with admin privileges can inject shell command arguments to add a file on the equipment

“An attacker with entry to an SMA SSL-VPN consumer account can chain these vulnerabilities to make a delicate system listing writable, elevate their privileges to SMA administrator, and write an executable file to a system listing,” Rapid7 mentioned in a report. “This chain ends in root-level distant code execution.”

Cybersecurity

CVE-2025-32819 is assessed to be a patch bypass for a beforehand recognized flaw reported by NCC Group in December 2021.

The cybersecurity firm famous that CVE-2025-32819 could have been exploited within the wild as a zero-day primarily based on identified indicators of compromise (IoCs) and incident response investigations. Nonetheless, it is price noting that SonicWall makes no point out of the flaw being weaponized in real-world assaults.

The shortcomings, that affect SMA 100 Sequence together with SMA 200, 210, 400, 410, 500v, have been addressed in model 10.2.1.15-81sv.

The event comes as a number of safety flaws in SMA 100 Sequence gadgets have come underneath lively exploitation in latest weeks, together with CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475. Customers are suggested to replace their cases to the newest model for optimum safety.

Discovered this text attention-grabbing? Observe us on Twitter and LinkedIn to learn extra unique content material we put up.



RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments