logo

SonicWall Issues Patch for Exploit Chain in SMA Devices

ID: aa711e08-398d-5308-8cbf-6e78a9f58ec4

STIX ID: report--aa711e08-398d-5308-8cbf-6e78a9f58ec4

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-05-08

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

SonicWall disclosed three high-severity vulnerabilities in its Secure Mobile Access (SMA) 100 Series (CVE-2025-32819, CVE-2025-32820, CVE-2025-32821) that, when chained, let attackers delete the appliance database to reset the admin password, make arbitrary directories writable, and execute a root-level malicious file—resulting in near-total device compromise. Rapid7 assesses the primary flaw has been exploited in the wild; SonicWall issued firmware 10.2.1.15-81sv and recommends enabling MFA, using WAFs, and scanning for unauthorized logins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.