Critical SonicWall NetExtender CVE-2024-XXXX allows root file write
Key Takeaways SonicWall has addressed two critical security flaws in its NetExtender Linux client. The most severe vulnerability, CVE-2026-66152, is a path traversal flaw allowing arbitrary root file...
Key Takeaways
- SonicWall has addressed two critical security flaws in its NetExtender Linux client.
- The most severe vulnerability, CVE-2026-66152, is a path traversal flaw allowing arbitrary root file writes.
- A second flaw, CVE-2026-66153, is an improper link resolution issue affecting the auto-upgrade process.
- Both vulnerabilities impact NetExtender Linux Client versions 10.3.5 and earlier.
- Organizations should immediately upgrade to NetExtender Linux Client version 10.3.6 or later.
SonicWall has issued an urgent security notice regarding two significant vulnerabilities discovered in its NetExtender Linux client. Among these is a critical path traversal vulnerability that could enable an attacker to write arbitrary files to a system with root privileges.
Table Of Content
The affected software includes NetExtender Linux Client versions 10.3.5 and all prior releases. A patched version, 10.3.6, has been made available to address these issues. The more severe of the two, identified as CVE-2026-66152, has been assigned a CVSS score of 8.8, indicating a high level of risk.
According to SonicWall, the primary flaw stems from how the Linux client processes OPSWAT tarball archives. This vulnerability permits a remote attacker to exploit path traversal sequences, directing files to be extracted outside their intended directories.
Given that the extraction process operates with root permissions, successful exploitation of this vulnerability could lead to arbitrary file writes with the highest system privileges. This poses a severe risk for privilege escalation on Linux systems, as an attacker could potentially manipulate critical system files or introduce malicious scripts.
For instance, an attacker might overwrite vital configuration files, inject malicious scripts into directories accessed by privileged processes, or modify system startup files. The ultimate impact of such an attack would vary depending on the specific target environment, existing file permissions, and whether user interaction could be leveraged to facilitate a malicious update or archive.
SonicWall NetExtender Vulnerabilities
The critical vulnerability, CVE-2026-66152, is classified under CWE-29, or Path Traversal. This category encompasses attacks that leverage special path sequences, such as “..,” to break out of a designated directory. In scenarios involving archive extraction, insecure handling of file paths can permit specially crafted entries within an archive to be written to unintended locations on the system.
In addition to the path traversal flaw, SonicWall also resolved CVE-2026-66153, an improper link resolution vulnerability found in the NetExtender Linux client. This flaw affects the NEService auto-upgrade mechanism, which handles temporary files insecurely.
A local attacker with access to the system could exploit this weakness by manipulating file paths through symbolic links, potentially influencing where files are accessed or written. CVE-2026-66153 carries a CVSS score of 7.0 and falls under CWE-59, known as Improper Link Resolution Before File Access, or a symlink-following issue.
Such vulnerabilities become particularly dangerous when privileged software performs file operations in temporary locations that are either controlled by an attacker or are easily predictable. SonicWall’s advisory indicates that the path traversal vulnerability (CVE-2026-66152) has a network attack vector and requires user interaction, while the improper link resolution flaw (CVE-2026-66153) is a local attack necessitating low privileges but high attack complexity. Both vulnerabilities, if exploited, could compromise confidentiality, integrity, and availability.
As of now, SonicWall has stated there is no evidence suggesting either vulnerability has been exploited in the wild. However, given NetExtender’s widespread use for providing remote access to corporate networks, prompt patching is crucial for organizations utilizing the Linux client. The vulnerabilities are detailed in SonicWall advisory SNWLID-2026-0013, published on August 25, 2026. No workarounds are currently available.
It is important to note that Windows-based NetExtender client versions are not affected by these specific vulnerabilities.
What You Should Do
- Immediately upgrade all affected NetExtender Linux Client installations from version 10.3.5 or earlier to version 10.3.6 or later.
- Identify any unmanaged Linux endpoints within your network and verify the installed NetExtender client versions.
- Review privileged software update mechanisms for any unsafe archive extraction or temporary-file handling practices that could introduce similar vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.