logo

SonicWall urges admins to patch critical RCE flaw in SMA 100 devices

ID: de186b52-7bc6-55d7-aa4e-dab796eefa68

STIX ID: report--de186b52-7bc6-55d7-aa4e-dab796eefa68

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-07-24

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SonicWall has released a security advisory for SMA 100 series appliances addressing CVE-2025-40599, an authenticated arbitrary file upload vulnerability that can enable remote code execution; customers are urged to update to fixed releases, limit remote management, reset credentials, enforce MFA, and check for IoCs. The report also highlights active targeting of SMA 100 devices by an actor tracked as UNC6148, which has deployed the OVERSTEP rootkit (and may deploy Abyss ransomware) after stealing appliance credentials via multiple earlier vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.