PT-2025-51891 · Sonicwall · Sma 100 Series
Published
2025-12-17
·
Updated
2026-01-09
·
CVE-2025-40602
CVSS v2.0
7.1
High
| Vector | AV:N/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SonicWall SMA1000 versions prior to 12.4.3-03245 and 12.5.0-02283
SonicWall SMA 100 series appliances (affected versions not specified)
Description
A local privilege escalation vulnerability exists in the SonicWall SMA1000 appliance management console (AMC) due to insufficient authorization. This vulnerability, actively exploited in the wild, allows an attacker to escalate privileges. The vulnerability has been chained with other flaws to achieve root remote code execution. This issue affects SonicWall SMA1000 appliances and SMA 100 series appliances. There have been reports of this vulnerability being exploited in attacks, potentially leading to network entry.
Recommendations
Upgrade SonicWall SMA1000 to version 12.4.3-03245 or 12.5.0-02283.
Apply the latest hotfixes for SonicWall SMA 100 series appliances.
Restrict access to the AMC to administrative IP addresses only.
Fix
LPE
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sma 100 Series