← Vulnerability feed

Vulnerability record · CVE-2025-23006 · published 23 January 2025

CVE-2025-23006: SonicWall SMA1000 pre-auth deserialization allows OS command execution

Sonicwall · Sma8200v

The SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific conditions lets a remote unauthenticated attacker run arbitrary OS commands. It matters because the flaw is network-reachable with no credentials or user interaction, and it is already listed in CISA KEV with known ransomware use.

9.8 CVSS 3.1 Critical CISA KEV since 24 Jan 2025 Known ransomware use EPSS 23% · top 2.3% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
23%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
8Affected product versions listed by NVD
2References
24 Sep 2026Last modified by NVD

Description

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 pre-auth remote code execution, KEV-listed with known ransomware use, and a high EPSS percentile make this an urgent patch-first issue.

What it is

The SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific conditions lets a remote unauthenticated attacker run arbitrary OS commands. It matters because the flaw is network-reachable with no credentials or user interaction, and it is already listed in CISA KEV with known ransomware use.

Impact

An attacker gains remote code execution on the appliance with the privileges of the affected service, which can lead to full compromise of the management console and any data or credentials it holds.

Attack surface

Reachable over the network via the AMC/CMC interfaces (CVSS AV:N, PR:N, UI:N), so no authentication or user interaction is required. The description does not specify which endpoints or ports are involved.

Exploitation

CISA added it to KEV on 2025-01-24 with a 2025-02-14 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.23432 (97.7th percentile). The references are a vendor advisory and the KEV entry, with no public exploit details in the record.

What to do

  • Apply the SonicWall vendor advisory (SNWLID-2025-0002) update for SMA1000 AMC/CMC as the first action.
  • If a patch is not yet applied, follow CISA KEV required action: apply vendor mitigations or discontinue use of the product.
  • Restrict network access to AMC/CMC management interfaces to trusted administrative networks only.
  • Rotate credentials and secrets stored on or managed by affected appliances after remediation.
  • Monitor for and investigate any signs of prior compromise before patching, since exploitation is known to be active.

Detection

  • Review appliance and perimeter logs for unexpected inbound requests to AMC/CMC endpoints from untrusted sources.
  • Hunt for anomalous child processes or command execution spawned by the appliance management services.
  • Check for unexpected outbound connections or new accounts on SMA1000 appliances that could indicate post-exploitation activity.
  • Correlate appliance logs with KEV/EPSS-driven alerting for CVE-2025-23006 and validate patch state across all listed SMA/SRA models.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-23006 to the Known Exploited Vulnerabilities catalog on 24 January 2025 as "SonicWall SMA1000 Appliances Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 14 February 2025.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-23006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-15409SonicWall SMA1000 Work Place SSRF allows unauthenticated requestsThe SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests …KEVEPSS 6.8%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed6.6CVE-2025-40602SonicWall SMA1000 management console missing authorization privilege escalationThe SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to C…KEVEPSS 2.8%analysed7.2CVE-2026-4116Sonicwall sma6210 firmware vulnerabilityImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tu…EPSS 0.71%7.2CVE-2026-4112Sonicwall sma6210 firmware sql injection vulnerabilityImproper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic…EPSS 0.53%7.2CVE-2026-4113Sonicwall sma6210 firmware vulnerabilityAn observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user creden…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2025-23006), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.