SonicWall has released an urgent firmware update, version 10.2.2.2-92sv , for its Secure Mobile Access (SMA) 100 series appliances , aimed at detecting and removing the known OVERSTEP rootkit malware . The advisory, SNWLID-2025-0015 , published on September 22 , 2025, strongly recommends that all users of the SMA 210, 410, and 500v appliances apply the update immediately to protect themselves from persistent threats .
See also: SonicWall: Brute force attacks hit firewall configuration backups

This release introduces additional file inspection capabilities designed to clean malware from compromised systems. The update directly addresses threats identified in a July 2025 report by the Google Threat Intelligence Group (GTIG). Researchers analyzed a campaign by a malicious actor, tracked as UNC6148, that deployed the OVERSTEP malware to SonicWall SMA 100 appliances that were nearing end-of-life.
OVERSTEP is a sophisticated rootkit that allows attackers to maintain persistent access via hidden credentials, create a reverse shell, and extract sensitive data. The stolen files can include credentials, One-Time Password (OTP) seeds, and certificates, providing attackers with long-term persistence even after firmware updates.
See also: ACSC warns of SonicWall access vulnerability

The release of this firmware is a critical step in combating active exploitation. The GTIG report noted that the OVERSTEP rootkit was deployed on SonicWall SMA appliances approaching their end of support date of October 1, 2025.While Google researchers were unable to definitively determine the original access agent, they observed significant overlap between UNC6148 activity and incidents involving the Abyss ransomware.
In previous attacks, malicious actors installed web shells on SMA devices to maintain their foothold despite system updates. The SonicWall advisory acknowledges the risks highlighted by Google and urges administrators to implement the security measures described in a related July knowledge article. The company has actively addressed a series of vulnerabilities in SMA 100 devices throughout ’ the year.
In May 2025, it fixed three bugs (CVE-2025-32819, CVE-2025-32820, CVE-2025-32821) that could be combined for remote code execution. Another critical bug, CVE-2025-40599, was fixed in July to prevent authenticated arbitrary file uploads. SonicWall emphasizes that this new firmware is the primary solution for affected devices running versions 10.2.1.15-81sv and earlier.
See also: SonicWall: Disable SSL VPN due to ransomware

There is no workaround available. The advisory clarifies that the OVERSTEP vulnerability does not impact the SonicWall SSL VPN SMA 1000 or the SSL-VPN functionality running on its firewalls. Given the active threats and the upcoming end of support date for the SMA 100 series, organizations are advised to prioritize this update to prevent compromise and data exfiltration.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
