Loading HuntDB...

CVE-2025-40599

CRITICAL
Published 2025-07-23T13:13:45.791Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-40599. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
9.1
/10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

Available Exploits

No exploits available for this CVE.

Related News

SonicWall fixed critical flaw in SMA 100 devices exploited in Overstep malware attacks

SonicWall addressed a critical vulnerability, tracked as CVE-2025-40599 (CVSS score of 9.1), in SMA 100 appliances SonicWall addressed a critical vulnerability, tracked as CVE-2025-40599 (CVSS score of 9.1), in SMA 100 appliances. Experts warn customers to ch…

Securityaffairs.com 2025-07-24 12:59
Sonicwall fixes critical flaw in SMA appliances, urges customers to check for compromise (CVE-2025-40599)

Sonicwall is asking customers running specific Secure Mobile Access (SMA) 100 Series devices to patch a newly uncovered vulnerability (CVE-2025-40599) as soon as possible. “While there is currently no evidence that this vulnerability is being actively exploit…

Help Net Security 2025-07-24 10:11

Affected Products

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

Affected Products (ENISA)

sonicwall
sma 100 series

ENISA Scoring

CVSS Score (3.1)

9.1
/10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Score

0.120
probability

Data provided by ENISA EU Vulnerability Database. Last updated: July 25, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed CRITICAL

GHSA-9pr6-9rp3-fq9v

Advisory Details

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

CVSS Scoring

CVSS Score

9.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: July 23, 2025, Modified: July 23, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

4 posts
Reddit 1 month, 3 weeks ago
FutureSafeMSSP

UPDATE ON COORDINATED ATTACK ON SONICWALL SSL VPN Blackpoint Cyber’s Response Operations Center (BROC) has observed a marked escalation in threat activity [targeting SonicWall SSL VPN appliances](https://blackpointcyber.com/blog/blackpoint-threat-bulletin-sonicwall-firewall-appliances-targeted-by-threat-actors), with evidence suggesting coordinated efforts by multiple threat actors including the Akira Ransomware Group. Our BROC team just published a blog that outlines …

Reddit 1 month, 4 weeks ago
Steve_Dobbs_69

CVE-2025-40599: Exploitable Arbitrary File Upload Vulnerability in SMA 100 Series Web Management Interface

Reddit 2 months ago
_cybersecurity_

Critical RCE Flaws in Sophos and SonicWall Devices Demand Immediate Action **Sophos and SonicWall have issued urgent patches for critical vulnerabilities that could allow remote code execution on their firewall and SMA 100 devices.** **Key Points:** - Sophos Firewall vulnerabilities CVE-2025-6704 and CVE-2025-7624 are rated CVSS 9.8, allowing potential pre-auth …

Reddit 2 months ago
Erased321
Payload

CVE-2025-40599 - Post- Authentication Arbitrary File Upload Vulnerability – SMA 100 Series Another round for SMA100 series vulnerabilities. SonicWall PSIRT has confirmed a Post-Authentication Arbitrary File Upload Vulnerability affecting SMA 100 Series appliances, including SMA 210, 410, and 500v. This does not affect SMA 1000 Series or SSL-VPN running on …

References

Published: 2025-07-23T13:13:45.791Z
Last Modified: 2025-07-25T03:55:18.989Z
Copied to clipboard!