CVE Tools

Description

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

In plain language

AI Low urgency

SMA100 series web interfaces have a browser-based flaw that can trick a user into running an attacker’s code; update affected SMA 210, SMA 410, and SMA 500v devices.

Executive summary

Reflected XSS in the SMA100 series web interface allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim’s browser after the victim follows a crafted request.

If affected, business impact
Browser session theftUnauthorized interface actionsAdministrator account misuse

What to do now

  1. Check whether you run an SMA 210, SMA 410, or SMA 500v and record its current firmware version.
  2. Confirm whether its web management interface is reachable from the internet.
  3. Upgrade SMA 210, SMA 410, and SMA 500v firmware to 10.2.2.1-90sv or later.
  4. Until upgraded, limit web-interface access to trusted networks and avoid opening unsolicited device-management links.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:CC:LI:LA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:LConfidentiality
Low
I:LIntegrity
Low
A:NAvailability
None

Weaknesses

Affected Products

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-40598 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store