CVE-2025-32820

Published May 7, 2025

Last updated 2 months ago

Overview

Description
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
Source
PSIRT@sonicwall.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.3
Impact score
5.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Severity
HIGH

Weaknesses

PSIRT@sonicwall.com
CWE-22

Social media

Hype score
Not currently trending
  1. ⚠️Vulnerabilidades en los productos SonicWall ❗CVE-2025-32819 ❗CVE-2025-32820 ❗CVE-2025-32821 ➡️Más info: https://t.co/FT9dGtNU8B https://t.co/IRo7XHKe8t

    @CERTpy

    12 May 2025

    211 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  2. #SonicWall patched three SMA 100 vulnerabilities (CVE-2025-32819, CVE-2025-32820, and CVE-2025-32821), that could be chained by a #hacker to execute arbitrary code. #Cybersecurity #infosec https://t.co/iAe4zoW6ls https://t.co/rTF2viwO5J

    @twelvesec

    11 May 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. SonicWall has urged customers to patch three vulnerabilities (CVE-2025-32819, CVE-2025-32820, CVE-2025-32821) in its Secure Mobile Access (SMA) appliances, which can be exploited for remote code execution. https://t.co/Yyz5TluUgP

    @securityRSS

    9 May 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-32820 🔴 HIGH (8.3) 🏢 SonicWall - SMA100 🏗️ 10.2.1.14-75sv and earlier versions 🔗 https://t.co/WWEOVoSL3M #CyberCron #VulnAlert #InfoSec https://t.co/Y1avij3fzL

    @cybercronai

    9 May 2025

    203 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  5. SonicWall SMA 100 series patched 3 critical zero-day flaws! CVE-2025-32819 allows file deletion & factory resets, exploited in the wild, bypassing patches. CVE-2025-32820 enables remote privilege escalation. Stay updated! 🚨 #Security #Updates https://t.co/ex8tedOmra

    @TweetThreatNews

    8 May 2025

    67 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. SonicWall patches 3 critical flaws in SMA 100 devices, risking remote code execution and root access. CVE-2025-32819 & CVE-2025-32820 allow bypasses and file deletion. Stay alert! 🔒 #SMA #SecurityAlert #USA https://t.co/qCapODthxU

    @TweetThreatNews

    8 May 2025

    71 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-32820 A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA app… https://t.co/nyjoVAAyhj

    @CVEnew

    7 May 2025

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.