SonicWall urges admins to patch VPN flaw exploited in attacks
ID: c6a6fd6d-06ef-55fc-944c-2415191f97f9
STIX ID: report--c6a6fd6d-06ef-55fc-944c-2415191f97f9
Feed Name: Bleeping Computer
Threat Score
SonicWall urged customers to apply firmware 10.2.1.15-81sv or later to address three chained vulnerabilities in SMA100-series appliances (CVE-2025-32819/32820/32821) that allow an attacker with an SSLVPN account to reset admin credentials, make system directories writable, and achieve root remote code execution; Rapid7 reports the chain may have been used in the wild and recommends reviewing logs and enabling WAF and MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
