• News/
  • https://www.theregister.com/2025/01/23/sonicwall_critical_bug/

SonicWall releases patches for suspected zero-day bug

The Register
·
Connor Jones
·
Published Jan 23, 2025
·
Updated

SonicWall is warning customers of a critical vulnerability that was potentially already exploited as a zero-day. The bug affects SonicWall's Secure Mobile Access (SMA) line, specifically the SMA 1000 product. The company stated in an advisory on Thursday that a remote unauthenticated attacker could execute arbitrary OS commands "in specific conditions." SonicWall didn't specify what these conditions were, likely out of concern about giving criminals more details on how to exploit CVE-2025-23006, but given the 9.8 severity rating, it's safe to assume these conditions can be met in many cases. Regardless, The Register requested additional details from the vendor but its spokespeople simply referred us back to the advisory. What we do know is that CVE-2025-23006 affects the SMA 1000's Appliance Management Console (AMC) and Central Management Console (CMC), both of which are used for admin tasks including configuring and monitoring hardware and creating new admin accounts. Although little has been said about the nature of the vulnerability – again, likely to give defenders time to apply patches – we can infer some elements from the breakdown of the severity score calculation. The attack complexity is "low," no privileges are required for exploitation, and the risk to confidentiality, integrity, and system availability is rated "high" in all three categories. The vendor released hotfix version 12.4.3-02854 (platform-hotfix), nullifying the issue. All prior versions are considered ...

Read full article

Affected Software

4 affected components
SonicWall Secure Mobile Access=1000
SonicWall Appliance Management Console
SonicWall Central Management Console
SonicWall Secure Mobile Access=1000

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability identified in SonicWall's Secure Mobile Access (SMA) 1000 product.

2

What security implications are discussed in the article?

The article highlights the potential exploitation of a zero-day vulnerability affecting SonicWall's hardware, posing risks to customer security.

3

What products or software are affected by the vulnerability?

The affected products include SonicWall's Secure Mobile Access SMA 1000, Appliance Management Console, and Central Management Console.

4

Has SonicWall released any fixes for the vulnerability?

Yes, SonicWall has released patches to address the critical vulnerability in their Secure Mobile Access products.

5

What should customers do in response to this vulnerability?

Customers are advised to apply the updates provided by SonicWall to mitigate any security risks associated with the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203