Executive brief
SonicWall NetExtender is a Linux client used to establish secure remote access connections to corporate networks. A path traversal vulnerability in its file extractor component allows an attacker to write arbitrary files with root privileges, potentially enabling complete system compromise or installation of malware on affected client machines.
Technical details
The vulnerability is a path traversal flaw in the NetExtender Linux client's file extractor component. An attacker can exploit this to write arbitrary files to any location on the system with root privileges by crafting malicious input that bypasses path validation. The attack is network-reachable and does not require user authentication beyond initial NetExtender access. Successful exploitation allows arbitrary code execution with root-level privileges, enabling complete system takeover. Patches are expected from SonicWall.
Affected products
- SonicWall NetExtender Linux client
Timeline
- 2026-08-25: disclosed