CVE-2025-32819

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an...

Basic Information

CVE State
PUBLISHED
Reserved Date
April 11, 2025
Published Date
May 07, 2025
Last Updated
February 26, 2026
Vendor
SonicWall
Product
SMA100
Description
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
poc
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2025-07-16 17:25:30 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-07-16 17:25:30 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel