CVE-2025-40599

CRITICAL

Sonicwall Sma 210 Firmware < 10.2.2.1-90sv - Unrestricted File Upload

Title source: rule

Description

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

Scores

CVSS v3 9.1
EPSS 0.0019
EPSS Percentile 40.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-434
Status published

Affected Products (3)

sonicwall/sma_210_firmware < 10.2.2.1-90sv
sonicwall/sma_410_firmware < 10.2.2.1-90sv
sonicwall/sma_500v_firmware < 10.2.2.1-90sv

Timeline

Published Jul 23, 2025
Tracked Since Feb 18, 2026