CVE-2025-23006

CRITICAL(9.8)KEVRansomwareElevated Risk

SonicWall SMA1000 Appliances Deserialization Vulnerability

Description

CVE-2025-23006 is a critical-severity pre-authentication deserialization of untrusted data vulnerability in SonicWall SMA1000 series appliances that allows a remote unauthenticated attacker to execute arbitrary OS commands. With a CVSS v3.1 base score of 9.8, the flaw affects both the Appliance Management Console (AMC) and Central Management Console (CMC), enabling complete system compromise without any authentication. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of February 14, 2025, and critically, the ransomware association is classified as Known, indicating confirmed use in ransomware campaigns. The EPSS score of 41.59% at the 97.3rd percentile reflects extremely high exploitation probability consistent with active weaponization by ransomware operators.

KEV Information

Vendor
SonicWall
Product
SMA1000 Appliances
Date Added
January 24, 2025
Due Date
February 14, 2025
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
sonicwallsma8200v< 12.4.3-02854
sonicwallsma6200 firmware< 12.4.3-02854
sonicwallsma6210 firmware< 12.4.3-02854
sonicwallsma7200 firmware< 12.4.3-02854
sonicwallsma7210 firmware< 12.4.3-02854
sonicwallsra ex6000 firmware<= 12.4.3-02804
sonicwallsra ex7000 firmware<= 12.4.3-02804
sonicwallsra ex9000 firmware<= 12.4.3-02804

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

Unknown CWE

CVE-2025-23006 does not have a specific CWE assigned in the NVD database, but the vulnerability is explicitly described as a deserialization of untrusted data flaw. Insecure deserialization occurs when an application accepts serialized objects from untrusted sources without proper validation, allowing attackers to inject malicious objects that execute arbitrary code when deserialized. In the context of the SonicWall SMA1000 appliance, the Appliance Management Console (AMC) and Central Management Console (CMC) accept serialized data in pre-authentication contexts, meaning the vulnerable deserialization occurs before any authentication check is performed. An attacker can craft a malicious serialized payload that, when processed by the management console, instantiates attacker-controlled objects leading to arbitrary OS command execution on the underlying appliance operating system. This class of vulnerability is particularly dangerous in network security appliances because these devices sit at the network perimeter and typically have broad access to internal networks. Learn more about Deserialization of Untrusted Data

Impact Analysis

The impact of CVE-2025-23006 is catastrophic across all three dimensions of the CIA triad, each rated at the highest level. Confidentiality is fully compromised because arbitrary command execution on a SonicWall SMA1000 appliance provides access to all VPN session data, user credentials, SSL certificates, private keys, and network configuration details stored on the device. SMA1000 appliances serve as secure remote access gateways, meaning they handle and have access to all traffic flowing between remote users and the internal network.

Integrity suffers maximum impact as OS-level command execution enables the attacker to modify the appliance firmware, install persistent backdoors, alter VPN configurations to redirect traffic, inject malicious certificate authorities to enable man-in-the-middle attacks on VPN sessions, and manipulate access control lists to create unauthorized network paths. The attacker can also use the compromised appliance as a pivot point to attack internal network resources that the SMA gateway connects to.

Availability is critically threatened, and the Known ransomware association makes this dimension particularly urgent. Ransomware operators have been confirmed to use this vulnerability as an initial access vector, leveraging the compromised VPN appliance to gain a foothold in the target network before deploying ransomware across internal systems. The EPSS score of 41.59% at the 97.3rd percentile confirms massive exploitation activity. Affected products include SMA8200v, SMA6200, SMA6210, SMA7200, SMA7210, and the legacy SRA EX6000, EX7000, and EX9000 series. The pre-authentication nature of the vulnerability combined with the network-exposed position of these appliances creates maximum exposure for organizations that have not applied the patch.

Exploit Maturity

CVE-2025-23006 demonstrates confirmed maximum exploit maturity with active use in ransomware campaigns. CISA has included it in the Known Exploited Vulnerabilities catalog with a remediation deadline of February 14, 2025, and has flagged the ransomware association as Known — one of the most serious classifications in the KEV catalog. The EPSS score of 41.59% at the 97.3rd percentile reflects extreme exploitation activity. SonicWall published their advisory at SNWLID-2025-0002.

The pre-authentication nature of this vulnerability makes it exceptionally attractive to ransomware operators and initial access brokers. VPN appliances are prime targets because they are by design exposed to the internet and provide direct access to internal networks once compromised. The deserialization vulnerability requires no credentials, no user interaction, and no special conditions to exploit, meaning any internet-facing SMA1000 management console is immediately exploitable. Threat actors have been observed scanning for vulnerable SonicWall appliances at scale and using compromised devices to establish persistent access for subsequent ransomware deployment. The CISA KEV entry can be reviewed at the KEV catalog. The legacy SRA EX series appliances (EX6000, EX7000, EX9000) are particularly at risk because their patched firmware version represents the last available update, and organizations may still be running outdated firmware.

Remediation

  1. Update SMA1000 series appliances to firmware version 12.4.3-02854 or later immediately. This applies to SMA8200v, SMA6200, SMA6210, SMA7200, and SMA7210 models. Download the updated firmware from the SonicWall support portal and apply the update during an emergency maintenance window given the critical severity and confirmed ransomware exploitation.

  2. Assess and replace legacy SRA EX series appliances (EX6000, EX7000, EX9000) that are running firmware versions at or below 12.4.3-02804. These legacy devices should be treated as end-of-life and migrated to current SMA1000 series hardware with patched firmware. If immediate replacement is not possible, take these devices offline until they can be replaced.

  3. Restrict access to the AMC and CMC management interfaces so they are not accessible from the internet. The Appliance Management Console and Central Management Console should only be reachable from a dedicated management network or through an out-of-band management connection. Never expose SMA management interfaces directly to the public internet.

  4. Conduct a forensic assessment of any SMA1000 appliances that were running vulnerable firmware while exposed to the internet. Check for indicators of compromise including unexpected administrative accounts, modified firmware, unusual outbound connections, and evidence of credential harvesting. If compromise is suspected, assume that all VPN user credentials and certificates stored on the device have been exfiltrated.

  5. Reset all credentials accessible through the SMA appliance if there is any indication of compromise. This includes VPN user passwords, administrative credentials, LDAP/RADIUS shared secrets, SSL certificates, and any other authentication material configured on or accessible through the appliance. Implement multi-factor authentication for all VPN access if not already in place.

Technical Details

CVE-2025-23006 is a pre-authentication deserialization of untrusted data vulnerability in SonicWall SMA1000 appliances, characterized by the CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Breaking down the vector components: Attack Vector (AV:N) indicates the vulnerability is exploitable over the network, which is particularly significant for internet-facing VPN appliances. Attack Complexity (AC:L) means the exploit works reliably without special conditions. Privileges Required (PR:N) confirms that the deserialization occurs in a pre-authentication context, requiring no credentials whatsoever. User Interaction (UI:N) indicates no victim action is required. Scope (S:U) means the impact remains within the appliance's security context, but since the appliance runs on a full operating system, OS command execution provides complete device control.

The vulnerability exists in the web-based Appliance Management Console (AMC) and Central Management Console (CMC) components of the SMA1000 platform. These management interfaces process incoming HTTP requests that contain serialized data objects as part of their normal operation. Under specific conditions, the deserialization of these objects occurs before authentication is validated, creating a pre-authentication attack surface. An attacker can craft a malicious HTTP request containing a specially constructed serialized object that, when deserialized by the management console, triggers arbitrary code execution through object instantiation side effects or through manipulation of the deserialization process itself. The resulting code execution occurs at the OS level with the privileges of the management console process, which typically has sufficient permissions to execute arbitrary operating system commands. The fix in firmware version 12.4.3-02854 addresses the unsafe deserialization by implementing proper input validation and restricting the classes that can be deserialized in pre-authentication contexts. Affected products include the SMA8200v virtual appliance and the SMA6200, SMA6210, SMA7200, and SMA7210 hardware models, along with the legacy SRA EX6000, EX7000, and EX9000 appliances.

Frequently Asked Questions

What is CVE-2025-23006?

CVE-2025-23006 is a critical pre-authentication deserialization vulnerability in SonicWall SMA1000 series appliances that allows remote unauthenticated attackers to execute arbitrary OS commands. It carries a CVSS score of 9.8 and has a confirmed association with ransomware campaigns.

Is CVE-2025-23006 being used in ransomware attacks?

Yes, CISA has classified the ransomware association as "Known," confirming that threat actors are actively using this vulnerability as an initial access vector for ransomware deployment. Organizations should treat patching as an emergency priority.

Which SonicWall products are affected by CVE-2025-23006?

The vulnerability affects SMA8200v, SMA6200, SMA6210, SMA7200, SMA7210 (firmware before 12.4.3-02854) and legacy SRA EX6000, EX7000, and EX9000 appliances (firmware at or below 12.4.3-02804). Both the Appliance Management Console and Central Management Console are vulnerable.

Can CVE-2025-23006 be exploited without authentication?

Yes, this is a pre-authentication vulnerability, meaning no credentials are required to exploit it. Any internet-facing SMA1000 management interface running vulnerable firmware is immediately exploitable by any attacker who can reach it over the network.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score23.43%
EPSS Percentile97.6%

Dates

PublishedJanuary 23, 2025
Last ModifiedAugust 4, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.