CVE-2025-40596 Details
Description
A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
A stack-based buffer overflow vulnerability has been identified in the web interface of the SonicWall SMA100 series (including SMA 210, 410, and 500v) (versions 10.2.1.15-81sv and earlier). This vulnerability allows remote, unauthenticated attackers to cause a denial-of-service condition or potentially execute arbitrary code.
Users are advised to upgrade to SonicWall SMA100 series version 10.2.2.1-90sv or higher. Additionally, enabling multifactor authentication (MFA) and Web Application Firewall (WAF) on SMA100 can enhance security.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0012 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sonicwall sma 500v firmware | < 10.2.2.1-90sv |
CPE
Remediation
| |
| sonicwall sma 500v | All versions |
CPE
Remediation
| |
| sonicwall sma 210 firmware | < 10.2.2.1-90sv |
CPE
Remediation
| |
| sonicwall sma 210 | All versions |
CPE
Remediation
| |
| sonicwall sma 410 firmware | < 10.2.2.1-90sv |
CPE
Remediation
| |
| sonicwall sma 410 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2025 | Initial Analysis | [email protected] |
| Jul 23, 2025 | New CVE Received | [email protected] |
| Jul 23, 2025 | CVE Modified | CISA-ADP |