SonicWall has issued advisory (SNWLID-2025-0010), disclosing a critical Server-Side Request Forgery (SSRF) in the Work Place interface of the SMA1000 appliance.
See also: SonicWall patches three serious vulnerabilities in SMA devices

The vulnerability, which is listed as CVE-2025-40595, carries a CVSS v3 score of 7.2, indicating high severity. It was discovered by security researcher Ronan Kervella of Bishopfox and could allow remote, unauthenticated attackers to exploit encoded URLs to spoof the device and send unauthorized requests to unpredictable destinations, compromising the security of the system.
The vulnerability affects SonicWall SMA1000 appliances running firmware version 12.4.3-02925 (platform-hotfix) or earlier.
According to SonicWall's Product Security Incident Response Team (PSIRT), this issue in the Work Place interface could allow attackers to manipulate the behavior of the device, potentially gaining access to internal systems or external resources that should not be accessible.
The SMA1000 appliance, part of Secure Mobile Access (SMA) , is designed to provide secure remote access to organizations. The vulnerability affects all SMA1000 appliances running the specified firmware versions.
See also: CISA: SonicWall VPN flaw is actively used in attacks
It is worth noting that SonicWall has confirmed that its Firewall and SMA 100 series products are not affected by this issue.

To address the vulnerability, SonicWall has released a hotfix, version 12.4.3-02963 (platform-hotfix) and later, which completely eliminates the SSRF issue. The update is available for download through the MySonicWall portal (mysonicwall.com). SonicWall PSIRT strongly urges all SMA1000 appliance users to apply the hotfix immediately to protect their systems from potential exploitation.
The warning emphasizes that not upgrading can leave organizations exposed to attacks that could disrupt their operations or reveal sensitive data.
Unlike some vulnerabilities where temporary measures can mitigate the risk, SonicWall has stated that there is no workaround available for this issue. This highlights the criticality of applying the hotfix immediately, as attackers could potentially exploit the vulnerability without requiring authentication, thus increasing the likelihood of targeted attacks.
See also: SonicWall: Exploit released for vulnerability – Update immediately!
Server-Side Request Forgery (SSRF) vulnerabilities , such as those affecting SonicWall SMA1000 appliances , are among the most dangerous attack vectors for modern networks. Through SSRF, a malicious user can bypass security checks , execute requests within the internal network , and gain access to services that should not otherwise be accessible from the outside world.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
