CVE-2025-40603: SonicWall SMA 210 Firmware

Medium severity, CVSS 4.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.

Affected products

  • SonicWall SMA 210 Firmware: before 10.2.2.3 (fixed in 10.2.2.3)
  • SonicWall SMA 410 Firmware: before 10.2.2.3 (fixed in 10.2.2.3)
  • SonicWall SMA 500v Firmware: before 10.2.2.3 (fixed in 10.2.2.3)

Published 2025-10-31. Last modified 2026-10-07.