ZeroHour
Security Affairspublished ()ingested @securityaffairs

SonicWall warns of actively exploited flaw in SMA 100 AMC

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-40602CVE-2025-23006

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-23006
Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances

CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published.

Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections.

9.823% KEV ransomware
  • SonicWall SMA1000 Appliances — Appliance Management Console (AMC) and Central Management Console (CMC)
largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed
CVE-2025-40602
Missing Authorization Flaw in SonicWall SMA1000 Appliance Management Console

CVE-2025-40602 is a missing-authorization vulnerability (CWE-862, with CWE-250 unnecessary-privilege issues) in the appliance management console (AMC) of SonicWall's SMA1000 secure-access appliances, characterized by CISA as a privilege escalation flaw; the CVSS vector (AV:N/AC:H/PR:H/UI:N, CVSS 3.1 score 6.6) indicates it is reachable over the network but requires an attacker that already holds high privileges. An attacker who has obtained AMC access can invoke insufficiently authorized actions to escalate privileges and gain high-impact control of the appliance, with high confidentiality, integrity, and availability impact. Affected products are the SMA1000 appliance line — SMA 6200, 6210, 7200, and 7210 firmware and the SMA 8200V virtual appliance. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-17 and SonicWall has warned of active exploitation and shipped fixes, while EPSS estimates a 2.1% probability of exploitation within 30 days (81st percentile) and ransomware use is unknown.

Do: Apply the patched SMA1000 firmware identified in SonicWall's security advisory immediately (the source data does not specify the fixed version), and follow CISA BOD 22-01 guidance for cloud services or discontinue use if mitigations are unavailable. Until patched, restrict AMC access to trusted management networks or a VPN, and review appliance logs for indicators of unauthorized access since exploitation is confirmed in the wild.

6.62% KEV
  • SonicWall SMA1000 appliance - SMA 6200 firmware
  • SonicWall SMA1000 appliance - SMA 6210 firmware
  • SonicWall SMA1000 appliance - SMA 7200 firmware
  • +2 more
large≈10,000–100,000 SMA1000 appliances/management consoles deployed (exact internet-exposed count unknown)
Full article296 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 17, 2025

SonicWall warned users to patch a SMA1000 AMC flaw that was exploited as a zero-day privilege escalation vulnerability in attacks.

SonicWall urged customers to address a vulnerability, tracked as CVE-2025-40602, in the SMA1000 Appliance Management Console that was exploited as a zero-day in attacks in the wild.

The flaw is a local privilege escalation issue which is due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

“A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).” reads the advisory published by the company. “Please note that SonicWall Firewall products are not affected by this vulnerability.”

The vendor warned customers that the vulnerability was chained with CVE-2025-23006 (CVSS score 9.8) in zero-day attacks to escalate privileges. Sonicwall has not disclosed details about the attacks that exploited the flaw as a zero-day, nor the attackers’ motivations.

“This vulnerability was reported to be leveraged in combination with CVE-2025-23006 (CVSS score 9.8) to achieve unauthenticated remote code execution with root privileges. CVE-2025-23006 was remediated in build version 12.4.3-02854 (platform-hotfix) and higher versions (released on Jan 22, 2025).” continues the advisory.SonicWall PSIRT strongly advises users of the SMA1000 product to upgrade to the latest hotfix release version to address the vulnerability.”

The company addressed the vulnerability CVE-2025-23006 in January 2025 with the release of version 12.4.3-02854 (platform-hotfix). In late January, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) vulnerability, tracked as CVE-2025-23006 to its Known Exploited Vulnerabilities (KEV) catalog.

Clément Lecigne and Zander Work of the Google Threat Intelligence Group reported the vulnerability.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SMA1000)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185809/hacking/sonicwall-warns-of-actively-exploited-flaw-in-sma-100-amc.html