SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-40602

SonicWall SMA1000 Missing Authorization Vulnerability

KEVMEDIUM 6.6EPSS 2.11%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 December 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

CVSS 3.1
6.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
2.11% probability · 81th percentile
CISA KEV
Listed 17 December 2025 · due 24 December 2025
Weakness
CWE-250, CWE-862
Affected
sonicwall/sma6200 firmware · sonicwall/sma6210 firmware · sonicwall/sma7200 firmware · sonicwall/sma7210 firmware · sonicwall/sma8200v
Source
PSIRT@sonicwall.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable Check for signs of potential compromise on all internet accessible SonicWall SMA1000 instances after applying mitigations. For more information please see: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019 ; https://nvd.nist.gov/vuln/detail/CVE-2025-40602

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.