ZeroHour

CVE-2025-23006

KEV ransomwarelarge

Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances

CISA: SonicWall SMA1000 Appliances Deserialization Vulnerability

CVSS 3.1
9.8 critical
EPSS
23%p98
Published
()
KEV added
AI analysis

CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published.

What to do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections.

Affected
SonicWall SMA1000 Appliances — Appliance Management Console (AMC) and Central Management Console (CMC)
Estimated exposure
largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed — SonicWall's SMA product family has a very large installed base and public internet scans regularly surface tens of thousands of SonicWall SMA devices; the SMA1000 enterprise line is a minority subset of that base, so a tens-of-thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CISA Known Exploited Vulnerability
Affected
SonicWall SMA1000 Appliances
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
sma8200v, sma6200 firmware, sma6210 firmware, sma7200 firmware, sma7210 firmware, sra ex6000 firmware, sra ex7000 firmware, sra ex9000 firmware
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news