CVE-2025-40599
CRITICALSonicwall Sma 210 Firmware < 10.2.2.1-90sv - Unrestricted File Upload
Title source: ruleDescription
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.
Scores
CVSS v3
9.1
EPSS
0.0019
EPSS Percentile
40.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Classification
CWE
CWE-434
Status
published
Affected Products (3)
sonicwall/sma_210_firmware
< 10.2.2.1-90sv
sonicwall/sma_410_firmware
< 10.2.2.1-90sv
sonicwall/sma_500v_firmware
< 10.2.2.1-90sv
Timeline
Published
Jul 23, 2025
Tracked Since
Feb 18, 2026