• News/
  • https://www.theregister.com/2025/12/18/sonicwall_sma_1000_0day/

Another bad week for SonicWall as SMA 1000 zero-day under active exploit

The Register
·
Carly Page
·
Published Dec 18, 2025
·
Updated

SonicWall has warned customers of a zero-day flaw in its SMA 1000 remote-access appliance that's being actively exploited, potentially allowing attackers to escalate privileges and take over boxes. The bug, tracked as CVE-2025-40602, resides in the appliance management console of SonicWall's Secure Mobile Access (SMA) 1000 series and stems from missing or insufficient authorization checks that let authenticated attackers elevate their privileges. SonicWall's advisory says the vulnerability has been chained with another SMA 1000 flaw patched earlier this year (CVE-2025-23006) to enable unauthenticated remote code execution with root rights – a particularly nasty combo when weaponized in the wild. SonicWall's official notice, published this week, says users should update to the latest hotfix versions immediately and restrict access to the Appliance Management Console to trusted networks. The vendor's PSIRT team says the issue affects only SMA 1000 appliances and does not impact other SonicWall firewall products or SSL VPN functions, but the fact that attackers have already begun exploiting the flaw underscores how exposed remote-access infrastructure remains. Researchers tracking exposed devices report hundreds of SMA 1000 units visible on the open internet, meaning a large pool of potentially vulnerable targets if patches aren't applied quickly. SonicWall has been a frequent target for cybercrime crews in 2025. In September, the vendor disclosed a breach of its MySonicWall clo...

Read full article

Affected Software

1 affected component
SonicWall Secure Mobile Access=1000
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in the SonicWall SMA 1000 remote-access appliance that is currently being exploited.

2

What security implications are discussed in the article?

The article highlights that the zero-day flaw could allow attackers to escalate privileges and take control of affected systems.

3

What specific vulnerability is mentioned in the article?

The vulnerability is tracked as CVE-2025-40602 and affects the management console of SonicWall's Secure Mobile Access appliance.

4

Who is affected by the SonicWall SMA 1000 zero-day exploit?

Customers using the SonicWall SMA 1000 remote-access appliances are affected by this critical security issue.

5

What is the date of publication for this security advisory?

The article was published on December 18, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203