CVE-2025-32820
SMA100 Path Traversal Privilege Escalation Vulnerability
Description
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
INFO
Published Date :
May 7, 2025, 6:15 p.m.
Last Modified :
May 19, 2025, 3:12 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
Affected Products
                                            The following products are affected by CVE-2025-32820
                                            vulnerability.
                                            Even if cvefeed.io is aware of the exact versions of the
                                            products
                                            that
                                            are
                                            affected, the information is not represented in the table below.
                                        
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source | 
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | [email protected] | ||||
| CVSS 3.1 | HIGH | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 
Solution
- Update the SMA appliance to the latest version.
- Restrict access to SMA appliances.
- Monitor for suspicious file modifications.
References to Advisories, Solutions, and Tools
                                            Here, you will find a curated list of external links that provide in-depth
                                            information, practical solutions, and valuable tools related to
                                            CVE-2025-32820.
                                        
| URL | Resource | 
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011 | Vendor Advisory | 
CWE - Common Weakness Enumeration
            While CVE identifies
            specific instances of vulnerabilities, CWE categorizes the common flaws or
            weaknesses that can lead to vulnerabilities. CVE-2025-32820 is
            associated with the following CWEs:
        
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
            (CAPEC)
            stores attack patterns, which are descriptions of the common attributes and
            approaches employed by adversaries to exploit the CVE-2025-32820
            weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
			The following list is the news that have been mention
			CVE-2025-32820 vulnerability anywhere in the article.
		
 
									- 
                                                            
                                                                CybersecurityNews 
SonicWall Releases Urgent Update to Remove Rootkit Malware ‘OVERSTEP’ from SMA Devices
SonicWall has issued an urgent firmware update, version 10.2.2.2-92sv, for its Secure Mobile Access (SMA) 100 series appliances to detect and remove known rootkit malware. The advisory, SNWLID-2025-00 ... Read more
 
									- 
                                                            
                                                                BleepingComputer 
SonicWall urges admins to patch critical RCE flaw in SMA 100 devices
SonicWall urges customers to patch SMA 100 series appliances against a critical authenticated arbitrary file upload vulnerability that can let attackers gain remote code execution. The security flaw ( ... Read more
 
									- 
                                                            
                                                                Dark Reading 
SonicWall Issues Patch for Exploit Chain in SMA Devices
Source: Sundry Photography via Alamy Stock PhotoSonicWall has fixed three high-severity vulnerabilities affecting its unified secure access gateway devices, one of which has already been exploited in ... Read more
 
									- 
                                                            
                                                                The Hacker News 
SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root
Network Security / Vulnerability SonicWall has released patches to address three security flaws affecting SMA 100 Secure Mobile Access (SMA) appliances that could be fashioned to result in remote code ... Read more
 
									- 
                                                            
                                                                Help Net Security 
Yet another SonicWall SMA100 vulnerability exploited in the wild (CVE-2025-32819)
SonicWall has fixed multiple vulnerabilities affecting its SMA100 Series devices, one of which (CVE-2025-32819) appears to be a patch bypass for an arbitrary file delete vulnerability that was exploit ... Read more
 
									- 
                                                            
                                                                security.nl 
SonicWall-lek dat voor fabrieksreset zorgt mogelijk misbruikt bij aanvallen
Een kwetsbaarheid in SonicWall SMA 100-gateways die voor een fabrieksreset kan zorgen is mogelijk misbruikt bij aanvallen, zo laat securitybedrijf Rapid7 weten. SonicWall heeft gisteren updates uitgeb ... Read more
 
									- 
                                                            
                                                                BleepingComputer 
SonicWall urges admins to patch VPN flaw exploited in attacks
SonicWall has urged its customers to patch three security vulnerabilities affecting its Secure Mobile Access (SMA) appliances, one of them tagged as exploited in attacks. Discovered and reported by Ra ... Read more
 
									- 
                                                            
                                                                Cyber Security News 
Multiple SonicWall SMA 100 Vulnerabilities Let Attackers Compromise Systems
SonicWall has disclosed multiple high-severity vulnerabilities affecting its Secure Mobile Access (SMA) 100 series products. Security researchers from Rapid7 discovered three significant post-authenti ... Read more
                The following table lists the changes that have been made to the
                CVE-2025-32820 vulnerability over time.
            
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
- 
                            Initial Analysis by [email protected]May. 19, 2025 Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_100_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.2.1.15-81sv OR cpe:2.3:h:sonicwall:sma_100:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.2.1.15-81sv OR cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.2.1.15-81sv OR cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.2.1.15-81sv OR cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.2.1.15-81sv OR cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.2.1.15-81sv OR cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:* Added Reference Type SonicWALL, Inc.: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011 Types: Vendor Advisory 
- 
                            CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0May. 07, 2025 Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H 
- 
                            New CVE Received by [email protected]May. 07, 2025 Action Type Old Value New Value Added Description A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable. Added CWE CWE-22 Added Reference https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011 
 
                         
                         
                         
                                             
                                            