Vulnerability record · CVE-2025-40596 · published 23 July 2025
CVE-2025-40596: SonicWall SMA100 web interface stack buffer overflow
Sonicwall · Sma 500v Firmware
The SMA100 series web interface contains a stack-based buffer overflow (CWE-121) reachable by a remote, unauthenticated attacker. Successful exploitation can cause denial of service or potentially allow code execution on the appliance.
Description
A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Automated analysis
high priorityUnauthenticated remote stack overflow on an internet-facing appliance with very high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
The SMA100 series web interface contains a stack-based buffer overflow (CWE-121) reachable by a remote, unauthenticated attacker. Successful exploitation can cause denial of service or potentially allow code execution on the appliance.
Impact
An attacker can crash or disrupt the SMA100 appliance, and depending on memory layout may achieve code execution on the device. The CVSS vector rates confidentiality, integrity and availability impacts as low.
Attack surface
Reached over the network through the SMA100 web interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify which endpoint or parameter is vulnerable.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.56488 (99th percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Apply the SonicWall PSIRT fix referenced in advisory SNWLID-2025-0012 for SMA 500v, SMA 210 and SMA 410 firmware.
- Restrict management and web interface access to trusted networks or VPN rather than exposing it to the internet.
- Monitor vendor advisories for updated firmware and re-apply if a revised build is released.
- Enable logging and alerting on crashes or restarts of the SMA100 web service to catch exploitation attempts.
Detection
- Monitor SMA100 web service processes for unexpected crashes, restarts or core dumps.
- Inspect web access logs for malformed or oversized requests to the SMA100 management interface.
- Alert on anomalous outbound connections or new processes on the appliance that could indicate post-exploitation code execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0012 | Vendor Advisory |
Track CVE-2025-40596 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-40596), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.