CVE-2025-40597: Buffer Overflow
Published Jul 23, 2025
·Updated
A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
Affected Software
6 affected components
All of the following
SonicWall Sma 500v Firmware<10.2.2.1-90sv
SonicWall Sma 500v
All of the following
SonicWall Sma 210 Firmware<10.2.2.1-90sv
SonicWall Sma 210
All of the following
SonicWall Sma 410 Firmware<10.2.2.1-90sv
SonicWall Sma 410
Event History
Jul 23, 2025
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40597?
CVE-2025-40597 has a high severity due to its potential to cause Denial of Service (DoS) and possibly allow for code execution.
2
How do I fix CVE-2025-40597?
To fix CVE-2025-40597, update the affected SonicWall SMA firmware to at least version 10.2.2.1-90sv.
3
What devices are affected by CVE-2025-40597?
CVE-2025-40597 affects SonicWall SMA 100 series devices, including the SMA 500v, 210, and 410 firmware versions up to 10.2.2.1-90sv.
4
Can CVE-2025-40597 be exploited remotely?
Yes, CVE-2025-40597 can be exploited by remote, unauthenticated attackers.
5
What are the potential consequences of CVE-2025-40597?
The potential consequences of CVE-2025-40597 include Denial of Service (DoS) and possible remote code execution.