CVE-2025-40595: SSRF
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40595?
The severity of CVE-2025-40595 is considered high due to its potential exploitation by unauthenticated remote attackers.
How do I fix CVE-2025-40595?
To mitigate CVE-2025-40595, update the SMA1000 Appliance to the latest firmware version provided by SonicWall.
What types of attacks can CVE-2025-40595 enable?
CVE-2025-40595 can enable server-side request forgery attacks, potentially allowing attackers to access internal resources.
Who is affected by CVE-2025-40595?
CVE-2025-40595 affects users of the SMA1000 Appliance listening on the Work Place interface.
Is authentication required to exploit CVE-2025-40595?
No, CVE-2025-40595 can be exploited by unauthenticated attackers using encoded URLs.