CVE-2025-40598
largeReflected XSS in SonicWall SMA100 Series Web Interface
CVE-2025-40598 is a reflected cross-site scripting flaw in the web interface of SonicWall's SMA100 series secure remote-access appliances. An unauthenticated attacker must craft a malicious link that, when clicked by a user of the appliance's interface, causes attacker-controlled JavaScript to run in that user's browser (the CVSS 'UI:R' requirement reflects this user interaction). Successful exploitation lets the attacker execute arbitrary JavaScript in the context of the trusted SMA site, potentially hijacking sessions, capturing credentials, or performing actions as the victim. Organizations running SMA 210, SMA 410, or SMA 500v appliances — typically deployed as SSL-VPN/remote-access gateways and often internet-exposed — are affected. No exploitation has been confirmed yet (not in CISA KEV, no public PoC), but the 48.7% EPSS score (99th percentile) indicates a high probability of exploitation within 30 days.
What to do: Apply the patched SMA 100-series firmware released by SonicWall as soon as the advisory's fixed versions are confirmed (do not delay upgrades on internet-facing SMA 210/410/500v units). Where possible, restrict network access to the appliance's web interface, and caution users against clicking unsolicited links that point to the SMA portal. Review web server logs for requests containing embedded script or redirect parameters that could indicate attempted reflected-XSS exploitation.
| SonicWall SMA 210 Firmware | — |
| SonicWall SMA 410 Firmware | — |
| SonicWall SMA 500v Firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
- Vendors
- sonicwall
- Products
- sma 500v firmware, sma 210 firmware, sma 410 firmware
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N