SonicWall has released urgent patches for a local privilege escalation vulnerability (CVE-2025-40602) in its Secure Mobile Access (SMA) 1000 appliances, following reports of active exploitation in the wild. Attackers have been chaining this flaw with a previously patched deserialization vulnerability (CVE-2025-23006) to achieve unauthenticated remote code execution with root privileges on affected devices. The vulnerabilities impact the Appliance Management Console (AMC) and Central Management Console (CMC), and SonicWall has advised customers to upgrade to the latest hotfix versions and restrict management interface access to mitigate risk.
Security advisories from multiple sources, including government agencies and SonicWall itself, emphasize the criticality of patching due to the widespread use of SMA1000 appliances in large enterprises and critical infrastructure. Over 950 internet-exposed SMA1000 devices have been identified, heightening concerns about potential exploitation. No indicators of compromise have been released, but organizations are urged to apply the fixes immediately and review their exposure to the AMC and SSH interfaces to prevent further attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On December 17, 2025, the Canadian Centre for Cyber Security issued alert AV25-845 highlighting SonicWall's advisory and affected SMA versions. It urged administrators to review SonicWall guidance and apply the recommended updates.
In its December 17, 2025 disclosure, SonicWall said attackers were chaining CVE-2025-40602 with the previously patched CVE-2025-23006. The combination enables unauthenticated remote code execution with root privileges on vulnerable SMA 1000 appliances.
On December 17, 2025, SonicWall disclosed CVE-2025-40602, an actively exploited local privilege escalation flaw in the SMA 1000 Appliance Management Console caused by insufficient authorization. The company released hotfixes, credited Google Threat Intelligence Group researchers Clément Lecigne and Zander Work with reporting the issue, and urged customers to restrict management access and patch immediately.
At an unspecified point after exploitation of CVE-2025-23006 became known, the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog. This reflected official recognition that the vulnerability was being actively exploited.
Earlier in January 2025, SonicWall remediated CVE-2025-23006, a critical deserialization vulnerability in SMA 1000 appliances. Later reporting said this flaw could be chained with CVE-2025-40602 to achieve unauthenticated remote code execution with root privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
secpod.com
Open sourcethecyberthrone.in
Open sourcego.theregister.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcepsirt.global.sonicwall.com
Open sourcetenable.com
Open sourcearcticwolf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.