HomeSecuritySonicWall patches critical SMA 100 vulnerability

SonicWall patches critical SMA 100 vulnerability

SonicWall on Wednesday announced the release of security updates for a critical vulnerability in its Secure Mobile Access (SMA) 100 series of secure access devices , urging organizations to take immediate action following recent Overstep malware attacks .

See also: SonicWall SMA appliances compromised with OVERSTEP rootkit

SonicWall SMA 100

The new vulnerability, with identifier CVE-2025-40599 and CVSS score 9.1, concerns an issue with arbitrary file uploads via the SMA 100 web management interface.

The flaw could be exploited by remote attackers to send arbitrary files to the system, which could lead to remote code execution (RCE). According to advisory , attackers would need administrative privileges to exploit the security issue.

The fixes for the vulnerability were included in the SMA 100 Series software release 10.2.2.1-90sv and are available for the SMA 210, 410, and 500v products . The SMA1000 Series SonicWall SSL VPN products and SSL-VPNs running on SonicWall firewalls are not affected

According to the company, there is no evidence that the CVE-2025-40599 vulnerability has been actively exploited. However, based on Google’s recent report of attacks by the UNC6148 installing the Overstep malware on SonicWall SMA 100 appliances, it is recommended that all organizations take immediate steps to secure their appliances.

See also: SonicWall: Fake NetExtender steals VPN credentials

Google has identified that hackers used compromised administrator credentials to gain access to fully updated devices and infect them. The credentials were likely obtained before the updates were applied, by exploiting known vulnerabilities such as CVE-2025-32819, CVE-2024-38475, CVE-2021-20035, CVE-2021-20038 , and CVE-2021-20039.

SonicWall patches critical SMA 100 vulnerability

Since compromised credentials can be used to exploit the new vulnerability and achieve remote code execution (RCE), organizations using SMA 100 series devices should look for indications of compromise (IoCs) related to UNC6148 group attacks.

Organizations using the SMA 500v virtual product are advised to back up the OVA file, export the settings, remove the virtual machine and all associated files, download a new OVA from SonicWall, install it on a hypervisor, and restore the settings.

See also: SonicWall SMA1000 vulnerability allows remote access

On Wednesday, SonicWall also announced security updates for three serious vulnerabilities in the SMA 100 series, including two buffer overflow (CVE-2025-40596 and CVE-2025-40597) that could lead to a denial of service (DoS) condition, as well as an XSS vulnerability (CVE-2025-40598) that allows execution of arbitrary JavaScript code.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS