Vulnerability record · CVE-2025-23006 · published 23 January 2025
CVE-2025-23006: SonicWall SMA1000 pre-auth deserialization allows OS command execution
Sonicwall · Sma8200v
The SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific conditions lets a remote unauthenticated attacker run arbitrary OS commands. It matters because the flaw is network-reachable with no credentials or user interaction, and it is already listed in CISA KEV with known ransomware use.
Description
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 pre-auth remote code execution, KEV-listed with known ransomware use, and a high EPSS percentile make this an urgent patch-first issue.
What it is
The SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific conditions lets a remote unauthenticated attacker run arbitrary OS commands. It matters because the flaw is network-reachable with no credentials or user interaction, and it is already listed in CISA KEV with known ransomware use.
Impact
An attacker gains remote code execution on the appliance with the privileges of the affected service, which can lead to full compromise of the management console and any data or credentials it holds.
Attack surface
Reachable over the network via the AMC/CMC interfaces (CVSS AV:N, PR:N, UI:N), so no authentication or user interaction is required. The description does not specify which endpoints or ports are involved.
Exploitation
CISA added it to KEV on 2025-01-24 with a 2025-02-14 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.23432 (97.7th percentile). The references are a vendor advisory and the KEV entry, with no public exploit details in the record.
What to do
- Apply the SonicWall vendor advisory (SNWLID-2025-0002) update for SMA1000 AMC/CMC as the first action.
- If a patch is not yet applied, follow CISA KEV required action: apply vendor mitigations or discontinue use of the product.
- Restrict network access to AMC/CMC management interfaces to trusted administrative networks only.
- Rotate credentials and secrets stored on or managed by affected appliances after remediation.
- Monitor for and investigate any signs of prior compromise before patching, since exploitation is known to be active.
Detection
- Review appliance and perimeter logs for unexpected inbound requests to AMC/CMC endpoints from untrusted sources.
- Hunt for anomalous child processes or command execution spawned by the appliance management services.
- Check for unexpected outbound connections or new accounts on SMA1000 appliances that could indicate post-exploitation activity.
- Correlate appliance logs with KEV/EPSS-driven alerting for CVE-2025-23006 and validate patch state across all listed SMA/SRA models.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-23006 to the Known Exploited Vulnerabilities catalog on 24 January 2025 as "SonicWall SMA1000 Appliances Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 14 February 2025.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-23006 | US Government Resource |
Track CVE-2025-23006 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-23006), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.