Description
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
In plain language
AI Low urgencySMA100 series web interfaces have a browser-based flaw that can trick a user into running an attacker’s code; update affected SMA 210, SMA 410, and SMA 500v devices.
Reflected XSS in the SMA100 series web interface allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim’s browser after the victim follows a crafted request.
What to do now
- Check whether you run an SMA 210, SMA 410, or SMA 500v and record its current firmware version.
- Confirm whether its web management interface is reachable from the internet.
- Upgrade SMA 210, SMA 410, and SMA 500v firmware to 10.2.2.1-90sv or later.
- Until upgraded, limit web-interface access to trusted networks and avoid opening unsolicited device-management links.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-40598 and every CVE in our database. Create a free account — no credit card required.
Create Free Account