CVE-2025-32819

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sonicwall:sma_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

History

19 May 2025, 15:13

Type Values Removed Values Added
First Time Sonicwall sma 100 Firmware
Sonicwall
Sonicwall sma 210
Sonicwall sma 400
Sonicwall sma 400 Firmware
Sonicwall sma 500v
Sonicwall sma 200
Sonicwall sma 410
Sonicwall sma 100
Sonicwall sma 210 Firmware
Sonicwall sma 500v Firmware
Sonicwall sma 200 Firmware
Sonicwall sma 410 Firmware
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011 - Vendor Advisory
References () https://old.rapid7.com/blog/post/2025/05/07/multiple-vulnerabilities-in-sonicwall-sma-100-series-2025/ - () https://old.rapid7.com/blog/post/2025/05/07/multiple-vulnerabilities-in-sonicwall-sma-100-series-2025/ - Exploit, Third Party Advisory
CPE cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_100:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_100_firmware:*:*:*:*:*:*:*:*

12 May 2025, 14:15

Type Values Removed Values Added
References
  • () https://old.rapid7.com/blog/post/2025/05/07/multiple-vulnerabilities-in-sonicwall-sma-100-series-2025/ -

08 May 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en SMA100 permite que un atacante remoto autenticado con privilegios de usuario SSLVPN evite las verificaciones de path traversal y elimine un archivo arbitrario, lo que potencialmente puede resultar en un reinicio a la configuración predeterminada de fábrica.

07 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 18:15

Updated : 2025-05-19 15:13


NVD link : CVE-2025-32819

Mitre link : CVE-2025-32819

CVE.ORG link : CVE-2025-32819


JSON object : View

Products Affected

sonicwall

  • sma_400_firmware
  • sma_400
  • sma_200
  • sma_410_firmware
  • sma_210_firmware
  • sma_500v_firmware
  • sma_100_firmware
  • sma_410
  • sma_210
  • sma_500v
  • sma_100
  • sma_200_firmware
CWE
CWE-552

Files or Directories Accessible to External Parties