CVE-2025-40602 Details
Description
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
A local privilege escalation vulnerability has been identified in the SonicWall SMA1000 appliance management console. This vulnerability arises from insufficient authorization, allowing unauthorized users to gain elevated privileges.
Users are advised to upgrade to SonicWall SMA1000 version 12.4.3-03245 (platform-hotfix) or 12.5.0-02283 (platform-hotfix). The latest platform-hotfix can be downloaded from mysonicwall.com. As a workaround, restrict access to the Appliance Management Console (AMC) by allowing SSH access only via VPN or specific admin IPs, and disable the SSL VPN management interface and SSH access from the public internet.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602 | CISA-ADP | US Government Resource |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| SonicWall SMA1000 Missing Authorization Vulnerability | Dec 17, 2025 | Dec 24, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sonicwall sma6200 firmware | < 12.4.3-03245 >= 12.5.0, < 12.5.0-02283 |
CPE
Remediation
| |
| sonicwall sma6200 | All versions |
CPE
Remediation
| |
| sonicwall sma6210 firmware | < 12.4.3-03245 >= 12.5.0, < 12.5.0-02283 |
CPE
Remediation
| |
| sonicwall sma6210 | All versions |
CPE
Remediation
| |
| sonicwall sma7200 firmware | < 12.4.3-03245 >= 12.5.0, < 12.5.0-02283 |
CPE
Remediation
| |
| sonicwall sma7200 | All versions |
CPE
Remediation
| |
| sonicwall sma7210 firmware | < 12.4.3-03245 >= 12.5.0, < 12.5.0-02283 |
CPE
Remediation
| |
| sonicwall sma7210 | All versions |
CPE
Remediation
| |
| sonicwall sma8200v | < 12.4.3-03245 >= 12.5.0, < 12.5.0-02283 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 19, 2025 | Initial Analysis | [email protected] |
| Dec 18, 2025 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | New CVE Received | [email protected] |