CVE-2025-40602
Description
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
In plain language
AI Act nowIf you run a SonicWall SMA1000 appliance (including SMA6200/SMA6210/SMA7200/SMA7210/SMA8200v) and an attacker already has a high-privilege login, this SMA management console flaw can let them take complete control of the device—this is serious and you should fix it.
CVE-2025-40602 is a permission-check failure (CWE-250/CWE-862) in the SonicWall SMA1000 Appliance Management Console (AMC) that allows an authenticated high-privilege admin to bypass authorization and escalate to complete device control via network access to the web management interface; it is listed in CISA KEV.
What to do now
- Check which SonicWall appliance model you run (SMA1000 / SMA6200 / SMA6210 / SMA7200 / SMA7210 / SMA8200v) and your current AMC firmware version.
- If your device is on one of the affected firmware families, plan to upgrade to the fixed firmware: 12.4.3-03245.
- If you cannot upgrade before the due date, follow SonicWall’s mitigation guidance from the vendor advisory (and consider disabling or tightly restricting access to the AMC web management interface from untrusted networks).
- After upgrading, verify the firmware is actually running (not just downloaded) and review admin activity/logs for any recent suspicious management-console actions.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
4 techniquesReferences
- SonicWall SMA 1000 appliances under attack via zero-day flawsen-us·Help Net Security· Exploited SonicWall SMA 1000 Appliances zero-day
- SonicWall warns of actively exploited SMA1000 zero-day flawsen-us·BleepingComputer· Exploited SMA1000 zero-day
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangsen-us·BleepingComputer· Exploited SMA1000 Qilin
- SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)en-us·Help Net Security· Exploited Secure Mobile Access (SMA) 1000 Series appliances zero-day
- Look What You Made Us Patch: 2025 Zero-Days in Reviewen-us·Mandiant· Exploited GTIG zero-day tracking UNC5221
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-40602 and every CVE in our database. Create a free account — no credit card required.
Create Free Account