Vulnerability record · CVE-2025-40598 · published 23 July 2025
CVE-2025-40598: SonicWall SMA100 web interface reflected XSS
Sonicwall · Sma 500v Firmware
The SMA100 series web interface reflects user-supplied input without proper neutralization, allowing a reflected cross-site scripting condition. Because the affected devices are remote-access gateways, a successful attack can run script in the context of a victim's authenticated session.
Description
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 6.1 medium severity with required user interaction, but high EPSS and exposure of internet-facing remote-access gateways raise the practical risk.
What it is
The SMA100 series web interface reflects user-supplied input without proper neutralization, allowing a reflected cross-site scripting condition. Because the affected devices are remote-access gateways, a successful attack can run script in the context of a victim's authenticated session.
Impact
An attacker can execute arbitrary JavaScript in a victim's browser session, potentially stealing session tokens or performing actions as the victim. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network through the SMA100 web interface with no authentication required, but exploitation requires the victim to interact with a crafted link or page (UI:R).
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS is high at roughly 0.51 (98.9th percentile), and a third-party advisory from WatchTowr covers this CVE alongside related SMA100 flaws.
What to do
- Apply the SonicWall PSIRT advisory SNWLID-2025-0012 firmware update for SMA100 series appliances.
- Restrict management and user web interface access to trusted networks or VPN where feasible.
- Deploy or tune WAF/input filtering to block reflected script payloads against the SMA100 web interface.
- Educate users not to click unsolicited links to the SMA100 login or portal pages.
Detection
- Monitor web logs for requests containing script tags or encoded JavaScript in parameters to SMA100 interface paths.
- Alert on anomalous authenticated session activity following visits to crafted SMA100 URLs.
- Review proxy and IDS/IPS logs for known XSS payload patterns targeting the SMA100 web interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0012 | Vendor Advisory |
| https://labs.watchtowr.com/stack-overflows-heap-overflows-and-existential-dread-sonicwall-sma100-cve-2025-40596-cve-2025 | Third Party Advisory |
Track CVE-2025-40598 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-40598), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.