HomeDefault status
unknown
10.2.1.15-81sv and earlier versions
affected
Description
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
10.2.1.15-81sv and earlier versions
Credits
Dawid Skomski of SonicWall PSIRT
References
psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014