CVE-2024-12806: SonicWall SonicOS

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

Affected products

  • SonicWall SonicOS: up to and including 6.5.4.15-117n; up to and including 7.0.1-5161; version 7.1.2-7019 only; version 8.0.0-8035 only

Published 2025-01-09. Last modified 2026-06-17.