ZeroHour

CVE-2025-40598

large

Reflected XSS in SonicWall SMA100 Series Web Interface

CVSS 3.1
6.1 medium
EPSS
49%p99
Published
()
Modified
AI analysis

CVE-2025-40598 is a reflected cross-site scripting flaw in the web interface of SonicWall's SMA100 series secure remote-access appliances. An unauthenticated attacker must craft a malicious link that, when clicked by a user of the appliance's interface, causes attacker-controlled JavaScript to run in that user's browser (the CVSS 'UI:R' requirement reflects this user interaction). Successful exploitation lets the attacker execute arbitrary JavaScript in the context of the trusted SMA site, potentially hijacking sessions, capturing credentials, or performing actions as the victim. Organizations running SMA 210, SMA 410, or SMA 500v appliances — typically deployed as SSL-VPN/remote-access gateways and often internet-exposed — are affected. No exploitation has been confirmed yet (not in CISA KEV, no public PoC), but the 48.7% EPSS score (99th percentile) indicates a high probability of exploitation within 30 days.

What to do: Apply the patched SMA 100-series firmware released by SonicWall as soon as the advisory's fixed versions are confirmed (do not delay upgrades on internet-facing SMA 210/410/500v units). Where possible, restrict network access to the appliance's web interface, and caution users against clicking unsolicited links that point to the SMA portal. Review web server logs for requests containing embedded script or redirect parameters that could indicate attempted reflected-XSS exploitation.

Affected
SonicWall SMA 210 Firmware
SonicWall SMA 410 Firmware
SonicWall SMA 500v Firmware
Estimated exposure
large≈10,000–100,000 internet-exposed SMA 100-series appliances (estimate) — SMA 100-series appliances serve as SSL-VPN/remote-access gateways that are normally internet-facing, and public internet-wide scans of SonicWall SSL-VPN/SMA portals have historically shown on the order of tens of thousands of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

Vendors
sonicwall
Products
sma 500v firmware, sma 210 firmware, sma 410 firmware
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news