Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2025-40602

Published 2025-12-18

Updated 3 months ago

Vendor/s

SonicWall

Product/s

SMA1000 appliance

Version/s

\* > 12.4.3-03245

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

6.6

/ 10

Medium

Severity Details

Base score

6.6 Medium

Attack vector

Network

Attack complexity

High

Privileges required

High

User interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2025-40602 is a privilege escalation vulnerability in SonicWall SMA1000 appliances. Active exploitation reported; update firmware immediately.

## Why this matters

CVE-2025-40602 represents a critical risk for organizations utilizing SonicWall SMA1000 series appliances. While its CVSS score is 6.6 (Medium), its inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog confirms active exploitation in the wild. The vulnerability stems from insufficient authorization in the Appliance Management Console (AMC), allowing an attacker with existing high privileges to escalate to even greater levels of control. This local privilege escalation can be the final step for an adversary to gain full persistence on the secure access gateway. Given the active threat, security teams should treat this as a high-priority remediation task despite the moderate severity score.

## CPE

SonicWall

| Product           | Version Start | Version End (excl.) | Status     |
| ----------------- | ------------- | ------------------- | ---------- |
| sma6200\_firmware | \*            | 12.4.3-03245        | vulnerable |
| sma6200\_firmware | 12.5.0        | 12.5.0-02283        | vulnerable |
| sma6200           | -             | -                   | unaffected |
| sma6210\_firmware | \*            | 12.4.3-03245        | vulnerable |
| sma6210\_firmware | 12.5.0        | 12.5.0-02283        | vulnerable |
| sma6210           | -             | -                   | unaffected |
| sma7200\_firmware | \*            | 12.4.3-03245        | vulnerable |
| sma7200\_firmware | 12.5.0        | 12.5.0-02283        | vulnerable |
| sma7200           | -             | -                   | unaffected |
| sma7210\_firmware | \*            | 12.4.3-03245        | vulnerable |
| sma7210\_firmware | 12.5.0        | 12.5.0-02283        | vulnerable |
| sma7210           | -             | -                   | unaffected |
| sma8200v          | \*            | 12.4.3-03245        | vulnerable |
| sma8200v          | 12.5.0        | 12.5.0-02283        | vulnerable |

## Related weakness (CWE)

CWE-250, CWE-862

## Remediation plan

1

### Apply official patches

Immediately download and install the security patches provided by SonicWall for the SMA1000 series as detailed in security advisory SNWLID-2025-0019.

2

### Update affected systems

Ensure all SMA6200, SMA6210, SMA7200, SMA7210, and SMA8200v appliances are running firmware versions 12.4.3-03245 or 12.5.0-02283 or later.

3

### Restrict access

Isolate the Appliance Management Console (AMC) from the public internet and restrict access to authorized administrative subnets using strict firewall rules and ACLs.

4

### Monitor for exploitation

Review appliance audit logs for unauthorized configuration changes, unexpected privilege elevation events, or administrative sessions originating from unfamiliar internal IP addresses.

## Detection Guidance

Detecting exploitation of CVE-2025-40602 requires monitoring SonicWall AMC logs for unusual administrative behavior. Watch for log entries indicating failed authorization attempts followed by successful high-privilege actions. Security teams should also inspect system logs for any unauthorized shell access or modifications to system-level configuration files. Since this involves privilege escalation, focus on identifying accounts that suddenly exhibit root-level capabilities or perform sensitive operations outside of scheduled maintenance windows.

## References

[https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019 Vendor Advisory ](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2025-40602 US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
