CVE-2025-32819
HIGHDescription
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
Is your site exposed to CVE-2025-32819?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sonicwall | sma_100_firmware |
| sonicwall | sma_100 |
| sonicwall | sma_200_firmware |
| sonicwall | sma_200 |
| sonicwall | sma_210_firmware |
| sonicwall | sma_210 |
| sonicwall | sma_400_firmware |
| sonicwall | sma_400 |
| sonicwall | sma_410_firmware |
| sonicwall | sma_410 |
| sonicwall | sma_500v_firmware |
| sonicwall | sma_500v |
References
Frequently Asked Questions
What is CVE-2025-32819? +
How severe is CVE-2025-32819? +
What products are affected by CVE-2025-32819? +
How do I check if I'm vulnerable to CVE-2025-32819? +
Related Vulnerabilities
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission …
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations …
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow …
Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations.This issue …
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to …
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server …