← Back to Threat Radar·Vendor focus

SonicWall Vulnerabilities Affecting Small Businesses

SonicWall firewall and VPN vulnerabilities actively exploited against small and medium businesses.

8
Total CVEs
0
Critical
0
High risk
0
CISA KEV
Last updated: April 21, 2026 · Data: NVD · CISA KEV · EPSS
CVE-2025-40596medium

A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

24
SMB SCORE
CVSS 7.3
EPSS 0.2%
CVE-2025-40597medium

A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

24
SMB SCORE
CVSS 7.5
EPSS 0.2%
CVE-2025-40599medium

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

23
SMB SCORE
CVSS 9.1
EPSS 0.2%
CVE-2025-40600medium

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

22
SMB SCORE
CVSS 9.8
EPSS 0.1%
CVE-2025-40598medium

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

22
SMB SCORE
CVSS 6.1
EPSS 0.1%
CVE-2025-40605medium

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

21
SMB SCORE
CVSS 5.3
EPSS 0.1%
CVE-2025-40601medium

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

20
SMB SCORE
CVSS 7.5
EPSS 0.0%
CVE-2025-40604low

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.

20
SMB SCORE
CVSS 9.8
EPSS 0.0%
Related — other vendors affecting SMB
Microsoft vulnerabilities →Fortinet vulnerabilities →Cisco vulnerabilities →Apache vulnerabilities →WordPress vulnerabilities →Veeam vulnerabilities →Synology vulnerabilities →QNAP vulnerabilities →