← Vulnerability feed

Vulnerability record · CVE-2025-40602 · published 18 December 2025

CVE-2025-40602: SonicWall SMA1000 management console missing authorization privilege escalation

Sonicwall · Sma6200 Firmware

The SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to CWE-250 and CWE-862. An actor who already holds high privileges on the console can bypass authorization checks and execute with unnecessary privileges, which matters because it lets a limited admin escalate to full control of the appliance.

6.6 CVSS 3.1 Medium CISA KEV since 17 Dec 2025 EPSS 2.8% · top 14.3% CWE-250 · Execution with unnecessary privilegesCWE-862 · Missing authorization
6.6CVSS 3.1 base score
2.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with known exploitation and a short remediation deadline, though it requires high privileges and has a medium CVSS score.

What it is

The SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to CWE-250 and CWE-862. An actor who already holds high privileges on the console can bypass authorization checks and execute with unnecessary privileges, which matters because it lets a limited admin escalate to full control of the appliance.

Impact

An attacker with existing high-privileged access to the AMC gains elevated execution on the appliance, potentially taking over the management console and the SMA1000 device itself.

Attack surface

The CVSS vector is network-reachable (AV:N) but requires high privileges (PR:H) and no user interaction (UI:N), so it is reached by an authenticated high-privileged user of the management console rather than an unauthenticated remote attacker.

Exploitation

CVE-2025-40602 was added to CISA KEV on 2025-12-17 with a remediation due date of 2025-12-24, indicating known exploitation; EPSS 30-day probability is 0.02083 (80.6th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the SonicWall vendor fix per PSIRT advisory SNWLID-2025-0019 as the first action.
  • If patching is not immediately possible, follow CISA BOD 22-01 guidance and the vendor's mitigations, or discontinue use of the affected SMA1000 appliances.
  • Restrict and audit AMC administrative access, limiting high-privileged accounts to the minimum necessary personnel.
  • Monitor for and investigate unexpected privilege changes or administrative actions on SMA1000 management consoles.

Detection

  • Review AMC audit logs for authorization failures or privilege escalation events on SMA1000 appliances.
  • Alert on new or modified high-privileged AMC accounts and on administrative actions outside normal change windows.
  • Correlate network access to the AMC management interface with authentication events to spot anomalous high-privileged sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-40602 to the Known Exploited Vulnerabilities catalog on 17 December 2025 as "SonicWall SMA1000 Missing Authorization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable Federal deadline 24 December 2025.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-40602 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-15409SonicWall SMA1000 Work Place SSRF allows unauthenticated requestsThe SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests …KEVEPSS 6.8%analysed9.8CVE-2025-23006SonicWall SMA1000 pre-auth deserialization allows OS command executionThe SMA1000 Appliance Management Console and Central Management Console deserialize untrusted data before authentication, which in specific condition…KEVEPSS 23%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed7.2CVE-2026-4116Sonicwall sma6210 firmware vulnerabilityImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tu…EPSS 0.71%7.2CVE-2026-4112Sonicwall sma6210 firmware sql injection vulnerabilityImproper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic…EPSS 0.53%7.2CVE-2026-4113Sonicwall sma6210 firmware vulnerabilityAn observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user creden…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2025-40602), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.