← Back to browse · API

CVE-2025-40599

Severity
CRITICAL
CVSS
9.1
EPSS
0.10434
Risk score
40.05
CISA KEV
No
PoC
No
Published
2025-07-23
Modified
2025-07-25
First seen
2026-08-07
Aliases
EUVD-2025-22450, GHSA-9PR6-9RP3-FQ9V
Products
SonicWall:SMA 100 Series 10.2.1.15-81sv and earlier versions
Sources
euvd EUVD-2025-22450

Description

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

References