Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges
SonicWall has issued a security advisory regarding a local privilege escalation vulnerability affecting its SMA1000 appliances.
SonicWall has issued a security advisory regarding a local privilege escalation vulnerability affecting its SMA1000 appliances.
The vulnerability, identified as CVE-2025-40602, allows attackers with access to the management console to gain elevated privileges, potentially leading to full system control. This issue arises from insufficient authorization checks within the SonicWall SMA1000 Appliance Management Console (AMC).
Field Value
Vulnerability Name SonicWall SMA1000 Local Privilege Escalation
CVE ID CVE-2025-40602
Advisory ID SNWLID-2025-0019
SonicWall has issued a security advisory regarding a local privilege escalation vulnerability affecting its SMA1000 appliances.
CVSS Score 6.6 (Medium)
Researchers have discovered that this vulnerability could be combined with another critical flaw to achieve unauthenticated remote code execution with root-level privileges. This poses a significant risk for organizations using SonicWall's remote access infrastructure.
The vulnerability impacts SMA1000 devices running platform-hotfix versions 12.4.3-03093 and earlier, as well as 12.5.0-02002 and earlier. It does not affect SSL-VPN functionality on standalone firewalls, thus limiting the exposure to SMA1000 appliance users.
Threat actors are exploiting CVE-2025-40602 in conjunction with CVE-2025-23006, which has a CVSS score of 9.8. This combination allows attackers to bypass authentication and execute malicious code with root access. The previous flaw was addressed in build version 12.4.3-02854, released on Jan 22, 2025.
SonicWall has released patched versions to address the vulnerability. Organizations are advised to upgrade to platform-hotfix 12.4.3-03245 or higher, or 12.5.0-02283 or higher. Security patches are available through mysonicwall.com for registered users.
Until the patching process is completed, SonicWall recommends implementing strict access controls on the Appliance Management Console. Administrators should restrict SSH access to company VPN connections or designated administrative IP addresses. Additionally, disabling public internet access to the AMC and SSH services is advised as a temporary measure.
SonicWall PSIRT urges all SMA1000 users to prioritize upgrading to the latest hotfix release. The active exploitation and critical nature of the vulnerability, especially when combined with CVE-2025-23006, necessitate urgent action to deploy fixes across the infrastructure.
Based on reporting by GBHackers.
