CVE-2025-40599

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
sonicwallCNA
---
---
CISA-ADPADP
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
sonicwallsma_210_firmware
𝑥
< 10.2.2.1-90sv
sonicwallsma_410_firmware
𝑥
< 10.2.2.1-90sv
sonicwallsma_500v_firmware
𝑥
< 10.2.2.1-90sv
𝑥
= Vulnerable software versions