A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
History

Thu, 07 Aug 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall sma 210
Sonicwall sma 210 Firmware
Sonicwall sma 410
Sonicwall sma 410 Firmware
Sonicwall sma 500v
Sonicwall sma 500v Firmware
CPEs cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
Vendors & Products Sonicwall
Sonicwall sma 210
Sonicwall sma 210 Firmware
Sonicwall sma 410
Sonicwall sma 410 Firmware
Sonicwall sma 500v
Sonicwall sma 500v Firmware

Tue, 29 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Jul 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 23 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
Description A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published: 2025-07-23T14:49:48.805Z

Updated: 2025-07-29T13:24:17.161Z

Reserved: 2025-04-16T08:34:51.361Z

Link: CVE-2025-40598

cve-icon Vulnrichment

Updated: 2025-07-23T15:10:00.743Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-23T15:15:32.490

Modified: 2025-08-07T14:36:07.667

Link: CVE-2025-40598

cve-icon Redhat

No data.