top of page
perceptive_background_267k.jpg

CVE-2025-40602: SonicWall Secure Mobile Access (SMA) 1000 Zero-Day Exploited

Published:

17 December 2025 at 15:27:25

Alert date:

17 December 2025 at 21:02:12

Source:

tenable.com

Click to open the original link from this advisory

CVE-2025-40602 is a local privilege escalation vulnerability in SonicWall SMA 1000 appliance management console that has been exploited in the wild in a chained attack with CVE-2025-23006, a deserialization vulnerability. The combination allows unauthenticated attackers to execute arbitrary code with root privileges on affected SonicWall Secure Mobile Access devices. SonicWall has released patches for both vulnerabilities. The SMA product line has historically been targeted by ransomware groups and featured in top routinely exploited vulnerabilities lists.

Technical details

Mitigation steps:

Affected products:

SonicWall Secure Mobile Access SMA 1000

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page