Path Traversal Vulnerability in SonicWall SMA100
CVE-2025-32820
8.3HIGH
What is CVE-2025-32820?
A vulnerability exists within SonicWall's SMA100 that enables a remote authenticated attacker with SSLVPN user privileges to exploit a path traversal flaw. By injecting specific sequences into the path, the attacker can gain unauthorized write access to any directory on the SMA appliance. This exposure can lead to potentially damaging modifications to the appliance's filesystem, putting sensitive data and overall system integrity at risk.
Affected Version(s)
SMA100 Linux 10.2.1.14-75sv and earlier versions
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved