Netextender SonicWall Netextender

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in SonicWall Netextender.

By the Year

In 2026 there have been 2 vulnerabilities in SonicWall Netextender with an average score of 7.9 out of ten. Last year, in 2025 Netextender had 2 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Netextender in 2026 could surpass last years number.




Year Vulnerabilities Average Score
2026 2 7.90
2025 2 0.00
2024 2 7.15
2023 3 7.63
2022 1 7.80
2021 1 5.30

It may take a day or so for new Netextender vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent SonicWall Netextender Security Vulnerabilities

SonicWall NetExtender Linux Client Temp File Path Manipulation in Auto-Upgrade
CVE-2026-66153 7 - High - August 25, 2026

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

insecure temporary file

SonicWall NetExtender: Path Traversal Enables Root Write via tarball
CVE-2026-66152 8.8 - High - August 25, 2026

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.

Path Traversal: '\..\filename'

Link Following in SonicWall NetExtender Windows Client
CVE-2025-23010 - April 10, 2025

An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths.

insecure temporary file

CVE-2025-23009: LPE in SonicWall NetExtender (32/64-bit) -> File Delete
CVE-2025-23009 - April 10, 2025

A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion.

Execution with Unnecessary Privileges

Arbitrary Code Exec in SonicWall SMA100 NetExtender <10.2.339 Windows Client
CVE-2024-29014 8.8 - High - July 18, 2024

Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update.

Code Injection

SonicWall Capture Client 3.7.10 & NetExtender <=10.2.337 DoS via sfpmonitor.sys Buffer Overflow
CVE-2023-6340 5.5 - Medium - January 18, 2024

SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.

Memory Corruption

DLL Search Order Hijack in SonicWall NetExtender <10.2.336
CVE-2023-44220 7.3 - High - October 27, 2023

SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.

DLL preloading

SonicWall NetExtender LPE via Pre-Logon on Windows
CVE-2023-44218 7.8 - High - October 03, 2023

A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.

SonicWall Net Extender MSI LPE 10.2.336 via Repair
CVE-2023-44217 7.8 - High - October 03, 2023

A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality.

A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions
CVE-2022-22281 7.8 - High - May 13, 2022

A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.

Classic Buffer Overflow

SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this
CVE-2020-5147 5.3 - Medium - January 09, 2021

SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.

Unquoted Search Path or Element

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv
CVE-2015-4173 - August 26, 2015

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

Unquoted Search Path or Element

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for SonicWall Netextender or by SonicWall? Click the Watch button to subscribe.

SonicWall
Vendor

subscribe