CVE-2015-2248: SonicWall Remote Access Firmware

Medium severity, CVSS 6.8. EPSS: 3.9% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark.

Affected products

  • SonicWall Remote Access Firmware: before 7.5.1.0-38sv (fixed in 7.5.1.0-38sv); from 8.0.0.0, before 8.0.0.1-16sv (fixed in 8.0.0.1-16sv)

Published 2015-05-01. Last modified 2026-06-17.