SonicWall Security Update – 04 May 2025

SonicWall has released a security update to fix one vulnerability affecting SonicWall SMA1000.

The addressed vulnerability could allow the remote attacker to perform a serverside request forgery (SSRF) which will cause the appliance to make requests to an unintended location.

Sonicwall SMA1000 Server-Side Request Forgery Vulnerability (CVE-2025-2170):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Server-Side Request Forgery (SSRF)
Vulnerabilities

CVE-2025-2170

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SonicWall Security Advisory

References