Improper Link Resolution in SonicWall NetExtender Client for Windows
CVE-2025-23010

7.2HIGH

Key Information:

Vendor

Sonicwall

Vendor
CVE Published:
10 April 2025

What is CVE-2025-23010?

An improper link resolution vulnerability exists in SonicWall NetExtender client for Windows, affecting both 32-bit and 64-bit versions. This vulnerability enables attackers to exploit the application's handling of file paths, potentially allowing unauthorized access to files and manipulation of sensitive data. For more details, refer to the vendor's advisory.

Affected Version(s)

NetExtender Windows 10.3.1 and earlier versions

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.