CVE-2025-23008: SonicWall Netextender

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker to modify configurations.

Affected products

  • SonicWall Netextender: up to and including 10.3.1

Published 2025-04-10. Last modified 2026-06-17.