A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
The product accepts input in the form of a slash absolute path ('/absolute/pathname/here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.
Link | Tags |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0004 | vendor advisory |