Executive brief
SonicWall NetExtender is a remote access client used to connect to corporate networks securely. The Linux version contains a flaw in how it handles temporary files during automatic software upgrades, allowing an attacker to manipulate file paths and potentially execute arbitrary code or modify system files with elevated privileges.
Technical details
The vulnerability exists in the NEService auto-upgrade mechanism on the Linux client, which insecurely handles temporary files without proper validation or isolation. This is a classic temporary file vulnerability (CWE-377/CWE-379) where predictable or unprotected temp file paths allow path traversal or symlink attacks. An attacker with local access to the system can manipulate file paths during the upgrade process to cause arbitrary file writes or code execution. The attack requires local system access but does not require authentication to the NetExtender service itself. Patches addressing this issue are available from SonicWall.
Affected products
- SonicWall NetExtender <unknown>
Timeline
- 2026-08-25: disclosed