CVE-2025-23006: SonicWall SMA1000 Appliances Deserialization Vulnerability
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Other sources
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23006?
CVE-2025-23006 has been classified with a high severity due to its potential to allow remote unauthenticated attackers to execute arbitrary code.
How do I fix CVE-2025-23006?
To remediate CVE-2025-23006, it is recommended to update the affected SonicWall SMA1000 Appliance Management Console and Central Management Console to the latest patched version.
Which products are affected by CVE-2025-23006?
CVE-2025-23006 affects SonicWall SMA1000 Appliance Management Console and Central Management Console, along with specific firmware versions for devices like SMA6200, SMA7200, and others.
Can CVE-2025-23006 be exploited remotely?
Yes, CVE-2025-23006 can be exploited by remote attackers without authentication under certain conditions.
What type of vulnerability is CVE-2025-23006?
CVE-2025-23006 is a pre-authentication deserialization vulnerability involving untrusted data.