CVE-2025-40602
SonicWall SMA1000 Missing Authorization Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 December 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
- CVSS 3.1
- 6.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Listed 17 December 2025 · due 24 December 2025
- Weakness
- CWE-250, CWE-862
- Affected
- sonicwall/sma6200 firmware · sonicwall/sma6210 firmware · sonicwall/sma7200 firmware · sonicwall/sma7210 firmware · sonicwall/sma8200v
- Source
- PSIRT@sonicwall.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable Check for signs of potential compromise on all internet accessible SonicWall SMA1000 instances after applying mitigations. For more information please see: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019 ; https://nvd.nist.gov/vuln/detail/CVE-2025-40602
References
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.