Path Traversal Vulnerability in SonicWall SMA100
CVE-2025-32820

8.8HIGH

Key Information:

Vendor

Sonicwall

Status
Vendor
CVE Published:
7 May 2025

Badges

đź“° News Worthy

What is CVE-2025-32820?

A vulnerability exists within SonicWall's SMA100 that enables a remote authenticated attacker with SSLVPN user privileges to exploit a path traversal flaw. By injecting specific sequences into the path, the attacker can gain unauthorized write access to any directory on the SMA appliance. This exposure can lead to potentially damaging modifications to the appliance's filesystem, putting sensitive data and overall system integrity at risk.

Affected Version(s)

SMA100 Linux 10.2.1.14-75sv and earlier versions

News Articles

Multiple SonicWall SMA 100 Vulnerabilities Let Attackers Compromise Systems

SonicWall has disclosed multiple high-severity vulnerabilities affecting its Secure Mobile Access (SMA) 100 series products. 

1 month ago

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by CybersecurityNews

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32820 : Path Traversal Vulnerability in SonicWall SMA100