CVE-2025-40597
A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 16, 2025
- Published Date
- July 23, 2025
- Last Updated
- July 25, 2025
- Vendor
- SonicWall
- Product
- SMA 100 Series
- Description
- A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
- Tags
- Score
- 0.05% (Percentile: 15.96%) as of 2025-07-28
- Exploitation
- none
- Automatable
- Yes
- Technical Impact
- total
- Exploited in the Wild
- Yes (2025-07-23 15:45:28 UTC) Source
edge
CVSS Scores
CVSS v3.1
7.5 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
SSVC Information
Exploit Status
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
SonicWall Security Advisories | 2025-07-23 15:45:22 UTC |
Recent Mentions
Stack Overflows, Heap Overflows, and Existential Dread (SonicWall SMA100 CVE-2025-40596, CVE-2025-40597 and CVE-2025-40598)
Source: Watchtower Labs • Published: 2025-07-28 21:38:47 UTC
It’s 2025, and at this point we’re convinced there’s a secret industry-wide pledge: every network appliance must include at least one trivially avoidable HTTP header parsing bug - preferably pre-auth. Bonus points if it involves sscanf and engineers who try to do the right
SonicWall SMA100 SSL-VPN Affected By Multiple Vulnerabilities
Source: SonicWall Security Advisories • Published: 2025-07-23 15:46:30 UTC
1) CVE-2025-40596 - Pre-Authentication Stack-Based Buffer Overflow VulnerabilityA Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
CVSS Score: 7.3
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-121: Stack-based Buffer Overflow
2) CVE-2025-40597 - Pre-Authentication Heap-Based Buffer Overflow VulnerabilityA Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
CVSS Score: 7.3
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-122: Heap-based Buffer Overflow
3) CVE-2025-40598 - Reflected Cross-Site Scripting (XSS) VulnerabilityA Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code. CVSS Score: 6.3
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
SonicWall strongly advises users of the SMA100 series products (SMA 210, 410, and 500v) to upgrade to the mentioned fixed release version to address these vulnerabilities. There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.
CVE: CVE-2025-40596, CVE-2025-40597, CVE-2025-40598
Last updated: July 23, 2025, 3:46 p.m.
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel