CVE-2025-40597

EUVD-2025-22453
A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Affected Products (NVD)
VendorProductVersion
sonicwallsma_500v_firmware
𝑥
< 10.2.2.1-90sv
sonicwallsma_210_firmware
𝑥
< 10.2.2.1-90sv
sonicwallsma_410_firmware
𝑥
< 10.2.2.1-90sv
𝑥
= Vulnerable software versions