SonicWall warned customers today to patch a vulnerability in the SonicWall SMA1000 Appliance Management Console (AMC) that was chained in zero-day attacks to escalate privileges. According to SonicWall, this medium-severity local privilege escalation security flaw (CVE-2025-40602) was reported by Clément Lecigne and Zander Work of the Google Threat Intelligence Group, and doesn't affect SSL-VPN running on SonicWall firewalls. "SonicWall PSIRT strongly advises users of the SMA1000 product to upgrade to the latest hotfix release version to address the vulnerability," the company said in a Wednesday advisory. Remote unauthenticated attackers chained this vulnerability with a critical-severity SMA1000 pre-authentication deserialization flaw (CVE-2025-23006) in zero-day attacks to execute arbitrary OS commands under specific conditions. "This vulnerability was reported to be leveraged in combination with CVE-2025-23006 (CVSS score 9.8) to achieve unauthenticated remote code execution with root privileges. CVE-2025-23006 was remediated in build version 12.4.3-02854 (platform-hotfix) and higher versions (released on Jan 22, 2025)." Internet watchdog Shadowserver currently tracks over 950 SMA1000 appliances exposed online, though some may already have been patched against this attack chain. SMA1000 is a secure remote access appliance used by large organizations to provide VPN access to corporate networks. Given their critical roles across enterprises, government, and critical infra...
Sonicwall warns of new SMA1000 zero-day exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Dec 17, 2025
·Updated
Affected Software
1 affected component
SonicWall SMA1000
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly discovered zero-day vulnerability in the SonicWall SMA1000 Appliance Management Console.
2
What security implications are discussed in the article?
The article highlights a medium-severity local privilege escalation flaw that can be exploited in attacks.
3
What products or software are affected by the vulnerability?
The vulnerability specifically affects the SonicWall SMA1000 appliances.
4
How should users respond to this security advisory?
Users are advised to promptly patch the vulnerability to prevent exploitation.
5
What is the designation of the reported vulnerability?
The vulnerability is designated as CVE-2025-40602.