CVE-2025-23006: SonicWall SMA1000 Appliances Deserialization Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-01-24. EPSS: 23.4% chance of exploitation in the next 30 days.
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Affected products
- SonicWall SMA6200 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
- SonicWall SMA6210 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
- SonicWall SMA7200 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
- SonicWall SMA7210 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
- SonicWall SMA8200V: before 12.4.3-02854 (fixed in 12.4.3-02854)
- SonicWall SRA EX6000 Firmware: up to and including 12.4.3-02804
- SonicWall SRA EX7000 Firmware: up to and including 12.4.3-02804
- SonicWall SRA EX9000 Firmware: up to and including 12.4.3-02804
Published 2025-01-23. Last modified 2026-09-24.