High severity8.8NVD Advisory· Published May 7, 2025· Updated Jun 17, 2026
CVE-2025-32820
CVE-2025-32820
Description
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
Affected products
8- cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.15-81sv
- cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.15-81sv
- cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.15-81sv
- cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.15-81sv
- cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.15-81sv
Patches
Vulnerability mechanics
References
1- psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011nvdVendor Advisory
News mentions
0No linked articles in our index yet.