Critical SonicWall VPN Vulnerabilities Actively Exploited: Immediate Patch Required
SonicWall has issued an urgent security advisory addressing multiple critical vulnerabilities in its Secure Mobile Access (SMA) series. These flaws-now confirmed to be actively exploited-pose a serious risk to organizations relying on SonicWall's SSL VPN appliances to secure remote access. What's at Stake? Three vulnerabilities (CVE-2025-32819, CVE-2025-32820, and CVE-2025-32821) have been disclosed affecting the following SMA appliances: SMA 200 SMA 210 SMA 400 SMA 410 SMA 500v When chained together, these vulnerabilities can allow an attacker with valid SSL VPN user credentials to execute arbitrary code with root privileges. This grants full system control and could be used to pivot into internal networks, exfiltrate data, or deploy ransomware. Breakdown of the Exploits: CVE-2025-32819: Enables attackers to delete the primary SQLite database and reset the admin password, giving them admin access to the web interface. CVE-2025-32820: A path traversal vulnerability that makes the /bin directory writable. CVE-2025-32821: Allows an attacker to…