ZeroHour

CVE-2025-40602

KEVlarge

Missing Authorization Flaw in SonicWall SMA1000 Appliance Management Console

CISA: SonicWall SMA1000 Missing Authorization Vulnerability

CVSS 3.1
6.6 medium
EPSS
2%p81
Published
()
KEV added
AI analysis

CVE-2025-40602 is a missing-authorization vulnerability (CWE-862, with CWE-250 unnecessary-privilege issues) in the appliance management console (AMC) of SonicWall's SMA1000 secure-access appliances, characterized by CISA as a privilege escalation flaw; the CVSS vector (AV:N/AC:H/PR:H/UI:N, CVSS 3.1 score 6.6) indicates it is reachable over the network but requires an attacker that already holds high privileges. An attacker who has obtained AMC access can invoke insufficiently authorized actions to escalate privileges and gain high-impact control of the appliance, with high confidentiality, integrity, and availability impact. Affected products are the SMA1000 appliance line — SMA 6200, 6210, 7200, and 7210 firmware and the SMA 8200V virtual appliance. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-17 and SonicWall has warned of active exploitation and shipped fixes, while EPSS estimates a 2.1% probability of exploitation within 30 days (81st percentile) and ransomware use is unknown.

What to do: Apply the patched SMA1000 firmware identified in SonicWall's security advisory immediately (the source data does not specify the fixed version), and follow CISA BOD 22-01 guidance for cloud services or discontinue use if mitigations are unavailable. Until patched, restrict AMC access to trusted management networks or a VPN, and review appliance logs for indicators of unauthorized access since exploitation is confirmed in the wild.

Affected
SonicWall SMA1000 appliance - SMA 6200 firmware
SonicWall SMA1000 appliance - SMA 6210 firmware
SonicWall SMA1000 appliance - SMA 7200 firmware
SonicWall SMA1000 appliance - SMA 7210 firmware
SonicWall SMA1000 series - SMA 8200V virtual appliance
Estimated exposure
large≈10,000–100,000 SMA1000 appliances/management consoles deployed (exact internet-exposed count unknown) — The SMA1000 series is SonicWall's enterprise-class secure-access appliance line deployed by thousands of organizations, and its AMC is typically reachable over the network, so this order-of-magnitude estimate is inferred from deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

CISA Known Exploited Vulnerability
Affected
SonicWall SMA1000 appliance
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable
Due date
Ransomware use
Unknown
Vendors
sonicwall
Products
sma6200 firmware, sma6210 firmware, sma7200 firmware, sma7210 firmware, sma8200v
Weakness
CWE-250, CWE-862
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news