ZeroHour

CVE-2025-40596

large

Unauthenticated Stack Buffer Overflow in SonicWall SMA100 Series Web Interface

CVSS 3.1
7.3 high
EPSS
56%p99
Published
()
Modified
AI analysis

CVE-2025-40596 is a stack-based buffer overflow (CWE-121) in the web interface of SonicWall's SMA100 series secure access appliances, affecting the SMA 210 and SMA 410 hardware models and the SMA 500v virtual appliance. It can be triggered remotely by an unauthenticated attacker sending crafted input to the appliance's web interface, requiring no valid credentials or user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation can crash the web interface to cause a denial of service and may potentially result in code execution on the appliance. Any organization running SMA100 series firmware (SMA 210, SMA 410, or SMA 500v) with the web interface reachable is affected, which is the typical deployment because the appliance portal and management interface are designed to be internet-facing. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known yet, but the high EPSS score (56.5% probability of exploitation within 30 days, 99th percentile) makes near-term exploitation attempts likely.

What to do: Upgrade all SMA 210, SMA 410, and SMA 500v appliances to the latest SMA100 series firmware from SonicWall, checking the SonicWall PSIRT advisory for CVE-2025-40596 for the exact fixed versions (not listed in this record). Until patching is complete, restrict access to the SMA web interface to trusted source addresses where feasible and monitor for web service crashes, appliance reboots, or anomalous requests, given the elevated likelihood of near-term exploitation indicated by the EPSS score.

Affected
SonicWall SMA 210 firmware (SMA100 series)
SonicWall SMA 410 firmware (SMA100 series)
SonicWall SMA 500v firmware (SMA100 series virtual appliance)
Estimated exposure
largetens of thousands of internet-exposed appliances (roughly 30,000-40,000 SMA 100 series web interfaces visible in public internet scans; installed base likely… — Public internet scans have historically shown on the order of 30,000-40,000 internet-reachable SonicWall SMA 100 series web interfaces, and because the SMA portal/management interface is by design exposed for remote access, the plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

Vendors
sonicwall
Products
sma 500v firmware, sma 210 firmware, sma 410 firmware
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news