
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40602 is a missing authorization / privilege escalation vulnerability in the SonicWall SMA1000 series Appliance Management Console (AMC). It affects SMA6200, SMA6210, SMA7200, SMA7210, and SMA8200v appliances running firmware versions prior to 12.4.3-03245 or 12.5.0-02283. SonicWall disclosed the vulnerability on December 17–18, 2025, and it was immediately added to the CISA Known Exploited Vulnerabilities (KEV) catalog the same day. It carries a CVSS v3.1 base score of 6.6 (Medium/High) (SonicWall PSIRT, CISA KEV).
The vulnerability is rooted in two weaknesses: CWE-862 (Missing Authorization) and CWE-250 (Execution with Unnecessary Privileges). Insufficient authorization checks within the SMA1000 AMC allow an authenticated user with high privileges to escalate those privileges further on the appliance, potentially achieving root-level control. The attack vector is network-based but requires high privileges and has high attack complexity, meaning an attacker must already have a foothold in the AMC before exploiting the flaw. Researchers have noted that CVE-2025-40602 can be chained with CVE-2025-23006 (a separate SMA1000 vulnerability) to construct an attack path that grants unauthenticated root remote code execution (Tenable Blog, Rescana).
Successful exploitation results in high confidentiality, integrity, and availability impacts, effectively granting an attacker complete control over the affected SMA1000 appliance. Because SMA1000 devices serve as secure remote access gateways, a compromised appliance can expose internal network segments to lateral movement, credential harvesting, and interception of VPN traffic. When chained with CVE-2025-23006, the attack can be initiated without any prior authentication, dramatically expanding the risk surface for organizations relying on these devices for perimeter access control (CISA KEV, Tenable Blog).
CVE-2025-40602 was actively exploited in the wild as a zero-day prior to SonicWall's public disclosure on December 17, 2025, and was added to the CISA KEV catalog the same day with a due date of December 24, 2025 (CISA KEV). At least two public proof-of-concept repositories exist on GitHub (PoC GitHub, PoC GitHub 2). The EPSS score is approximately 0.0186 (1.86%), though the confirmed in-the-wild exploitation and KEV listing make it a high-priority patching target regardless. No specific threat actor attribution has been publicly confirmed, but the CISA KEV entry notes the vulnerability is potentially associated with ransomware campaigns (CISA KEV, Tenable Blog).
SonicWall has released patched firmware versions: 12.4.3-03245 and 12.5.0-02283 for all affected appliances (SMA6200, SMA6210, SMA7200, SMA7210, SMA8200v). Organizations should update immediately, as CISA's KEV due date was December 24, 2025. As a workaround, restrict network access to the AMC interface to trusted administrative networks only and monitor for unauthorized access attempts. CISA also advises checking all internet-accessible SMA1000 instances for signs of compromise even after patching (SonicWall PSIRT, CISA KEV).
SonicWall's PSIRT published advisory SNWLID-2025-0019 on December 17–18, 2025, confirming active exploitation and urging immediate patching (SonicWall PSIRT). Tenable published a detailed blog post characterizing the vulnerability as a zero-day and highlighting the chaining risk with CVE-2025-23006 (Tenable Blog). The vulnerability received broad coverage from The Hacker News, BleepingComputer, Dark Reading, The Register, and CRN, with many outlets noting the simultaneous disclosure of zero-days across Cisco, SonicWall, and ASUS as a concerning trend. The r/sonicwall subreddit saw community frustration, with users expressing fatigue over recurring SonicWall vulnerabilities. Security researchers on Mastodon and Bluesky flagged the CISA KEV addition within hours of disclosure (The Hacker News, Security Affairs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."