CVE-2025-23006: SonicWall SMA1000 Appliances Deserialization Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-01-24. EPSS: 23.4% chance of exploitation in the next 30 days.

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

Affected products

  • SonicWall SMA6200 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
  • SonicWall SMA6210 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
  • SonicWall SMA7200 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
  • SonicWall SMA7210 Firmware: before 12.4.3-02854 (fixed in 12.4.3-02854)
  • SonicWall SMA8200V: before 12.4.3-02854 (fixed in 12.4.3-02854)
  • SonicWall SRA EX6000 Firmware: up to and including 12.4.3-02804
  • SonicWall SRA EX7000 Firmware: up to and including 12.4.3-02804
  • SonicWall SRA EX9000 Firmware: up to and including 12.4.3-02804

Published 2025-01-23. Last modified 2026-09-24.