Executive brief
SonicWall Network Security Manager (NSM) On-Prem is an administrative platform used to manage and monitor network security appliances. A zip slip vulnerability in its file upload and archive processing allows an attacker to extract malicious files to arbitrary locations on the server, potentially leading to remote code execution or complete system compromise.
Technical details
This is a zip slip vulnerability (CWE-22) in the archive extraction logic of NSM On-Prem's file upload functionality. An attacker can craft a malicious archive file with path traversal sequences (e.g., "../../../") in filenames that, when extracted, bypass intended directory restrictions and write files to arbitrary locations on the file system. The vulnerability is triggered during file upload and archive processing operations. Successful exploitation could allow an attacker to overwrite system files, inject code, or gain unauthorized access to the system. Patches are expected to be available through SonicWall's PSIRT advisory.
Affected products
- SonicWall Network Security Manager On-Prem
Timeline
- 2026-09-04: disclosed