ZeroHour

CVE-2025-40599

CVSS 3.1
9.1 critical
EPSS
13%p96
Published
()
Modified
Description

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

Vendors
sonicwall
Products
sma 210 firmware, sma 410 firmware, sma 500v firmware
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news