9.1
CVE-2025-40599
- EPSS 0.17%
- Veröffentlicht 23.07.2025 13:13:45
- Zuletzt bearbeitet 06.11.2025 16:41:11
- Quelle PSIRT@sonicwall.com
- CVE-Watchlists
- Unerledigt
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Sma 210 Firmware Version < 10.2.2.1-90sv
Sonicwall ≫ Sma 410 Firmware Version < 10.2.2.1-90sv
Sonicwall ≫ Sma 500v Firmware Version < 10.2.2.1-90sv
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.387 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.