SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
ID: 6188663b-dfef-5183-b1d9-02ce311564e2
STIX ID: report--6188663b-dfef-5183-b1d9-02ce311564e2
Feed Name: GBHackers
Threat Score
**SonicWall released updates addressing two vulnerabilities in NetExtender Linux Client:** CVE-2026-66152 is a path traversal in an OPSWAT tarball that can allow arbitrary file writes as root (CVSS 8.8), and CVE-2026-66153 is an insecure temporary-file/symlink handling issue in the NEService auto-upgrade (CVSS 7.0); administrators should upgrade to NetExtender 10.3.6 as SonicWall provides no workaround and reports no current evidence of exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
