HomeDefault status
unknown
10.2.1.15-81sv and earlier versions
affected
Description
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
10.2.1.15-81sv and earlier versions
Credits
Sina Kheirkhah
References
labs.watchtowr.com/...596-cve-2025-40597-and-cve-2025-40598/
psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0012