CVE-2025-2170: SonicWall SMA1000 Firmware
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.
Affected products
- SonicWall SMA1000 Firmware: before 12.4.3-02925 (fixed in 12.4.3-02925)
Published 2025-04-30. Last modified 2026-06-17.