CVE-2025-40602

9.5 CISA KEV

SonicWall · SMA1000 appliance

SonicWall SMA1000 appliances contain a local privilege escalation vulnerability in the management console due to missing authorization checks, which is currently being exploited in the wild.

Executive summary

This critical vulnerability in SonicWall SMA1000 appliances allows for local privilege escalation and is currently being actively exploited in the wild to facilitate remote code execution.

Vulnerability

The flaw is a local privilege escalation issue arising from insufficient authorization within the Appliance Management Console (AMC). While the vulnerability requires initial authentication, it is frequently chained with other vulnerabilities, such as CVE-2025-23006, to bypass authentication and achieve root-level remote code execution.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational infrastructure, as it grants unauthorized actors high-level administrative control over the affected appliance. With a CVSS score of 9.5, this represents a critical threat capable of leading to full system compromise, data theft, and persistent unauthorized access. The observed chaining of this flaw with other exploits significantly increases the risk of complete network breach.

Remediation

Immediate Action: Upgrade to SonicWall SMA 1000 Series version 12.4.3-03245 (platform-hotfix) or 12.5.0-02283 (platform-hotfix) or later immediately.

Proactive Monitoring: Monitor system logs for unauthorized administrative access attempts or anomalous behavior within the Appliance Management Console.

Compensating Controls: Restrict management console access to trusted internal IP addresses and employ multi-factor authentication to limit the ability of unauthorized users to gain the initial access required to trigger this flaw.

Exploitation status

Public Exploit Available: Yes, public Proof-of-Concept exploits are available on GitHub.

Analyst recommendation

Given the critical severity of this vulnerability and the confirmed evidence of active exploitation in the wild, immediate patching is required. Organizations should prioritize the deployment of the vendor-provided hotfixes to all affected SMA1000 appliances. Failure to remediate this issue exposes the enterprise to a high probability of compromise by sophisticated threat actors.

More SonicWall CVEs

Sources

Originally found and disclosed by Clément Lecigne and Zander Work of Google Threat Intelligence Group, per the CVE Program record.