SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code execution.
The vulnerabilities are listed below:
By infosecbulletin
/ Saturday , August 1 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
By infosecbulletin
/ Friday , July 31 2026
A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
By infosecbulletin
/ Friday , July 31 2026
Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
By infosecbulletin
/ Thursday , July 30 2026
NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
By infosecbulletin
/ Wednesday , July 29 2026
India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
By infosecbulletin
/ Tuesday , July 28 2026
CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
By infosecbulletin
/ Tuesday , July 28 2026
OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
By infosecbulletin
/ Tuesday , July 28 2026
ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
By infosecbulletin
/ Monday , July 27 2026
Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
By infosecbulletin
/ Monday , July 27 2026
Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
CVE-2025-32819 (CVSS score: 8.8) : A vulnerability in SMA100 lets an authenticated remote attacker with SSL-VPN user access bypass checks and delete any file, which could cause the device to reset to factory default settings.
CVE-2025-32820 (CVSS score: 8.3): “A remote attacker with SSL-VPN user privileges can alter directory permissions on the SMA appliance.”
CVE-2025-32821 (CVSS score: 6.7): “A vulnerability in SMA100 allows a remote authenticated attacker with SSL-VPN admin privileges to inject commands and upload a file to the appliance.”
“An attacker with access to an SMA SSL-VPN user account can chain these vulnerabilities to make a sensitive system directory writable, elevate their privileges to SMA administrator, and write an executable file to a system directory,” Rapid7 said in a report. “This chain results in root-level remote code execution.”
CVE-2025-32819 is seen as a way to bypass a fix for a previously found issue reported by NCC Group in December 2021.
Recent weeks have seen active exploitation of several security flaws in SMA 100 Series devices, including CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475. Users should update to the latest version to ensure optimal protection.
Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day