CVE-2025-40598: XSS
Published Jul 23, 2025
·Updated
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
Affected Software
7 affected components
SMA SMA100 series
All of the following
SonicWall Sma 500v Firmware<10.2.2.1-90sv
SonicWall Sma 500v
All of the following
SonicWall Sma 210 Firmware<10.2.2.1-90sv
SonicWall Sma 210
All of the following
SonicWall Sma 410 Firmware<10.2.2.1-90sv
SonicWall Sma 410
Event History
Jul 23, 2025
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40598?
CVE-2025-40598 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2025-40598?
To fix CVE-2025-40598, ensure that you apply the latest firmware updates provided by SMA for the SMA100 series.
3
Who is affected by CVE-2025-40598?
CVE-2025-40598 affects users of the SMA100 series web interface.
4
What type of vulnerability is CVE-2025-40598?
CVE-2025-40598 is a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-40598 be exploited by unauthenticated users?
Yes, CVE-2025-40598 can be exploited by remote unauthenticated attackers.