CVE-2007-5815

CRITICAL ⚠ Exploit

Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 before 2.5, allows remote attackers to delete arbitra...

Affects 3 products across 1 vendor.

BCS8.81
CVSS 2.010.0
EPSS4.5%
Percentile91th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability exists in the WebCacheCleaner ActiveX control of SonicWall SSL-VPN 200 before version 2.1 and SSL-VPN 2000/4000 before version 2.5, allowing remote attackers to delete arbitrary files through a full pathname in the argument to the FileDelete method.

BSID: BS-2007-GLOBAL-172947-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2007-5815?
A critical vulnerability exists in the WebCacheCleaner ActiveX control of SonicWall SSL-VPN 200 before version 2.1 and SSL-VPN 2000/4000 before version 2.5, allowing remote attackers to delete arbitrary files through a full pathname in the argument to the FileDelete method.
What is the CVSS score for CVE-2007-5815?
CVE-2007-5815 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 4.5%.
Is CVE-2007-5815 actively exploited?
Public exploit available for CVE-2007-5815. Exploitation risk elevated.
How do I remediate CVE-2007-5815?
Priority: IMMEDIATE. Advisory: http://secunia.com/advisories/27469 PSIRT: [email protected]
What systems are affected by CVE-2007-5815?
CVE-2007-5815 affects: Sonicwall, Sonicwall, Sonicwall.
Vulnerability Details
CVE IDCVE-2007-5815
BSIDBS-2007-GLOBAL-172947-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2007-11-05
Last Modified2026-06-16
ICS Relevance80%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 before 2.5, allows remote attackers to delete arbitrary files via a full pathname in the argument to the FileDelete method.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is an absolute path traversal issue in the WebCacheCleaner ActiveX control. Attackers can exploit this by providing a full pathname to the FileDelete method, which can lead to the deletion of arbitrary files on the target system.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Sonicwall Ssl Vpn 200 —
Sonicwall Ssl Vpn2000\/4000 —
Sonicwall Ssl Vpn2000/4000 —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 6901 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ Available — Reference
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Sonicwall
CVE-2026-15409 10.0 A Server-side request forgery (SSRF) vulnerability has been identified in the... CVE-2026-83548 10.0 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work ... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2016-2396 9.9 The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, an... CVE-2018-9866 9.8 A vulnerability in lack of validation of user-supplied parameters pass to XML...
View all Sonicwall CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →