CVE-2025-40602: SonicWall SMA1000 Missing Authorization Vulnerability

Medium severity, CVSS 6.6. Actively exploited: in CISA KEV since 2025-12-17. EPSS: 2.8% chance of exploitation in the next 30 days.

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Affected products

  • SonicWall SMA6200 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
  • SonicWall SMA6210 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
  • SonicWall SMA7200 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
  • SonicWall SMA7210 Firmware: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)
  • SonicWall SMA8200V: before 12.4.3-03245 (fixed in 12.4.3-03245); from 12.5.0, before 12.5.0-02283 (fixed in 12.5.0-02283)

Published 2025-12-18. Last modified 2026-06-17.