• News/
  • https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-rce-flaw-exploited-in-zero-day-attacks/

SonicWall warns of SMA1000 RCE flaw exploited in zero-day attacks

BleepingComputer
·
Bill Toulas
·
Published Jan 23, 2025
·
Updated

SonicWall is warning about a pre-authentication deserialization vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), with reports that it has been exploited as a zero-day in attacks. The flaw, tracked as CVE-2025-23006 and rated critical (CVSS v3 score: 9.8), could allow remote unauthenticated attackers to execute arbitrary OS commands under specific conditions. The vulnerability affects all firmware versions of the SMA100 appliance up to 12.4.3-02804 (platform-hotfix). SonicWall highlighted that it has received reports that the vulnerability was exploited as a zero-day in attacks. "SonicWall PSIRT has been notified of possible active exploitation of the referenced vulnerability by threat actors," warns the bulletin. "We strongly advises users of the SMA1000 product to upgrade to the hotfix release version to address the vulnerability." Microsoft's Threat Intelligence Center discovered the flaw, so more details about the exploitation activity and when it started might be shared by Microsoft at a later date. System administrators are recommended to upgrade to version 12.4.3-02854 (platform-hotfix) and later to mitigate the risk. SonicWall clarified that CVE-2025-23006 does not impact SMA 100 series products, so no action is required for them. Germany's Computer Emergency Response Team, CERT-Bund, also issued a warning on X urging admins to install the updates immediately.

Macnica researcher Yutaka Sejiyama told BleepingC...

Read full article

Affected Software

4 affected components
SonicWall SMA1000 Appliance Management Console (AMC)=up to 12.4.3-02804
SonicWall Central Management Console (CMC)=up to 12.4.3-02804
SonicWall SMA1000 Appliance Management Console
SonicWall Central Management Console

Frequently Asked Questions

1

What vulnerability has SonicWall reported in the article?

SonicWall reported a pre-authentication deserialization vulnerability affecting the SMA1000 Appliance Management Console and Central Management Console.

2

How has this vulnerability been exploited?

The vulnerability has reportedly been exploited in zero-day attacks.

3

Which versions of the affected software are impacted?

The affected versions are SonicWall SMA1000 Appliance Management Console and Central Management Console up to version 12.4.3-02804.

4

What are the security implications of this vulnerability?

The vulnerability could allow an attacker to execute remote code, leading to potential unauthorized access to systems.

5

What products are mentioned as being affected by this security issue?

The affected products are SonicWall SMA1000 Appliance Management Console and SonicWall Central Management Console.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203