CVE-2025-23009: SonicWall Netextender

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion.

Affected products

  • SonicWall Netextender: up to and including 10.3.1

Published 2025-04-10. Last modified 2026-06-17.