PT-2025-51891 · Sonicwall · Sma 100 Series

Published

2025-12-17

·

Updated

2026-01-09

·

CVE-2025-40602

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SonicWall SMA1000 versions prior to 12.4.3-03245 and 12.5.0-02283 SonicWall SMA 100 series appliances (affected versions not specified)
Description A local privilege escalation vulnerability exists in the SonicWall SMA1000 appliance management console (AMC) due to insufficient authorization. This vulnerability, actively exploited in the wild, allows an attacker to escalate privileges. The vulnerability has been chained with other flaws to achieve root remote code execution. This issue affects SonicWall SMA1000 appliances and SMA 100 series appliances. There have been reports of this vulnerability being exploited in attacks, potentially leading to network entry.
Recommendations Upgrade SonicWall SMA1000 to version 12.4.3-03245 or 12.5.0-02283. Apply the latest hotfixes for SonicWall SMA 100 series appliances. Restrict access to the AMC to administrative IP addresses only.

Fix

LPE

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-16145
CVE-2025-40602

Affected Products

Sma 100 Series