CVE-2025-40602: SonicWall SMA1000 Missing Authorization Vulnerability
Medium severity, CVSS 6.6. Actively exploited: in CISA KEV since 2025-12-17. EPSS: 2.8% chance of exploitation in the next 30 days.
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Affected products
- SonicWall SMA6200 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
- SonicWall SMA6210 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
- SonicWall SMA7200 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
- SonicWall SMA7210 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
- SonicWall SMA8200V: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
Published 2025-12-18. Last modified 2026-06-17.