CVE-2025-23006
SonicWall SMA1000 Appliances Deserialization Vulnerability
Description
CVE-2025-23006 is a critical-severity pre-authentication deserialization of untrusted data vulnerability in SonicWall SMA1000 series appliances that allows a remote unauthenticated attacker to execute arbitrary OS commands. With a CVSS v3.1 base score of 9.8, the flaw affects both the Appliance Management Console (AMC) and Central Management Console (CMC), enabling complete system compromise without any authentication. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of February 14, 2025, and critically, the ransomware association is classified as Known, indicating confirmed use in ransomware campaigns. The EPSS score of 41.59% at the 97.3rd percentile reflects extremely high exploitation probability consistent with active weaponization by ransomware operators.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| sonicwall | sma8200v | < 12.4.3-02854 |
| sonicwall | sma6200 firmware | < 12.4.3-02854 |
| sonicwall | sma6210 firmware | < 12.4.3-02854 |
| sonicwall | sma7200 firmware | < 12.4.3-02854 |
| sonicwall | sma7210 firmware | < 12.4.3-02854 |
| sonicwall | sra ex6000 firmware | <= 12.4.3-02804 |
| sonicwall | sra ex7000 firmware | <= 12.4.3-02804 |
| sonicwall | sra ex9000 firmware | <= 12.4.3-02804 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-23006(US Government Resource)
Weakness Type
Unknown CWE
CVE-2025-23006 does not have a specific CWE assigned in the NVD database, but the vulnerability is explicitly described as a deserialization of untrusted data flaw. Insecure deserialization occurs when an application accepts serialized objects from untrusted sources without proper validation, allowing attackers to inject malicious objects that execute arbitrary code when deserialized. In the context of the SonicWall SMA1000 appliance, the Appliance Management Console (AMC) and Central Management Console (CMC) accept serialized data in pre-authentication contexts, meaning the vulnerable deserialization occurs before any authentication check is performed. An attacker can craft a malicious serialized payload that, when processed by the management console, instantiates attacker-controlled objects leading to arbitrary OS command execution on the underlying appliance operating system. This class of vulnerability is particularly dangerous in network security appliances because these devices sit at the network perimeter and typically have broad access to internal networks. Learn more about Deserialization of Untrusted Data
Impact Analysis
The impact of CVE-2025-23006 is catastrophic across all three dimensions of the CIA triad, each rated at the highest level. Confidentiality is fully compromised because arbitrary command execution on a SonicWall SMA1000 appliance provides access to all VPN session data, user credentials, SSL certificates, private keys, and network configuration details stored on the device. SMA1000 appliances serve as secure remote access gateways, meaning they handle and have access to all traffic flowing between remote users and the internal network.
Integrity suffers maximum impact as OS-level command execution enables the attacker to modify the appliance firmware, install persistent backdoors, alter VPN configurations to redirect traffic, inject malicious certificate authorities to enable man-in-the-middle attacks on VPN sessions, and manipulate access control lists to create unauthorized network paths. The attacker can also use the compromised appliance as a pivot point to attack internal network resources that the SMA gateway connects to.
Availability is critically threatened, and the Known ransomware association makes this dimension particularly urgent. Ransomware operators have been confirmed to use this vulnerability as an initial access vector, leveraging the compromised VPN appliance to gain a foothold in the target network before deploying ransomware across internal systems. The EPSS score of 41.59% at the 97.3rd percentile confirms massive exploitation activity. Affected products include SMA8200v, SMA6200, SMA6210, SMA7200, SMA7210, and the legacy SRA EX6000, EX7000, and EX9000 series. The pre-authentication nature of the vulnerability combined with the network-exposed position of these appliances creates maximum exposure for organizations that have not applied the patch.
Exploit Maturity
CVE-2025-23006 demonstrates confirmed maximum exploit maturity with active use in ransomware campaigns. CISA has included it in the Known Exploited Vulnerabilities catalog with a remediation deadline of February 14, 2025, and has flagged the ransomware association as Known — one of the most serious classifications in the KEV catalog. The EPSS score of 41.59% at the 97.3rd percentile reflects extreme exploitation activity. SonicWall published their advisory at SNWLID-2025-0002.
The pre-authentication nature of this vulnerability makes it exceptionally attractive to ransomware operators and initial access brokers. VPN appliances are prime targets because they are by design exposed to the internet and provide direct access to internal networks once compromised. The deserialization vulnerability requires no credentials, no user interaction, and no special conditions to exploit, meaning any internet-facing SMA1000 management console is immediately exploitable. Threat actors have been observed scanning for vulnerable SonicWall appliances at scale and using compromised devices to establish persistent access for subsequent ransomware deployment. The CISA KEV entry can be reviewed at the KEV catalog. The legacy SRA EX series appliances (EX6000, EX7000, EX9000) are particularly at risk because their patched firmware version represents the last available update, and organizations may still be running outdated firmware.
Remediation
-
Update SMA1000 series appliances to firmware version 12.4.3-02854 or later immediately. This applies to SMA8200v, SMA6200, SMA6210, SMA7200, and SMA7210 models. Download the updated firmware from the SonicWall support portal and apply the update during an emergency maintenance window given the critical severity and confirmed ransomware exploitation.
-
Assess and replace legacy SRA EX series appliances (EX6000, EX7000, EX9000) that are running firmware versions at or below 12.4.3-02804. These legacy devices should be treated as end-of-life and migrated to current SMA1000 series hardware with patched firmware. If immediate replacement is not possible, take these devices offline until they can be replaced.
-
Restrict access to the AMC and CMC management interfaces so they are not accessible from the internet. The Appliance Management Console and Central Management Console should only be reachable from a dedicated management network or through an out-of-band management connection. Never expose SMA management interfaces directly to the public internet.
-
Conduct a forensic assessment of any SMA1000 appliances that were running vulnerable firmware while exposed to the internet. Check for indicators of compromise including unexpected administrative accounts, modified firmware, unusual outbound connections, and evidence of credential harvesting. If compromise is suspected, assume that all VPN user credentials and certificates stored on the device have been exfiltrated.
-
Reset all credentials accessible through the SMA appliance if there is any indication of compromise. This includes VPN user passwords, administrative credentials, LDAP/RADIUS shared secrets, SSL certificates, and any other authentication material configured on or accessible through the appliance. Implement multi-factor authentication for all VPN access if not already in place.
Technical Details
CVE-2025-23006 is a pre-authentication deserialization of untrusted data vulnerability in SonicWall SMA1000 appliances, characterized by the CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Breaking down the vector components: Attack Vector (AV:N) indicates the vulnerability is exploitable over the network, which is particularly significant for internet-facing VPN appliances. Attack Complexity (AC:L) means the exploit works reliably without special conditions. Privileges Required (PR:N) confirms that the deserialization occurs in a pre-authentication context, requiring no credentials whatsoever. User Interaction (UI:N) indicates no victim action is required. Scope (S:U) means the impact remains within the appliance's security context, but since the appliance runs on a full operating system, OS command execution provides complete device control.
The vulnerability exists in the web-based Appliance Management Console (AMC) and Central Management Console (CMC) components of the SMA1000 platform. These management interfaces process incoming HTTP requests that contain serialized data objects as part of their normal operation. Under specific conditions, the deserialization of these objects occurs before authentication is validated, creating a pre-authentication attack surface. An attacker can craft a malicious HTTP request containing a specially constructed serialized object that, when deserialized by the management console, triggers arbitrary code execution through object instantiation side effects or through manipulation of the deserialization process itself. The resulting code execution occurs at the OS level with the privileges of the management console process, which typically has sufficient permissions to execute arbitrary operating system commands. The fix in firmware version 12.4.3-02854 addresses the unsafe deserialization by implementing proper input validation and restricting the classes that can be deserialized in pre-authentication contexts. Affected products include the SMA8200v virtual appliance and the SMA6200, SMA6210, SMA7200, and SMA7210 hardware models, along with the legacy SRA EX6000, EX7000, and EX9000 appliances.
Frequently Asked Questions
What is CVE-2025-23006?
CVE-2025-23006 is a critical pre-authentication deserialization vulnerability in SonicWall SMA1000 series appliances that allows remote unauthenticated attackers to execute arbitrary OS commands. It carries a CVSS score of 9.8 and has a confirmed association with ransomware campaigns.
Is CVE-2025-23006 being used in ransomware attacks?
Yes, CISA has classified the ransomware association as "Known," confirming that threat actors are actively using this vulnerability as an initial access vector for ransomware deployment. Organizations should treat patching as an emergency priority.
Which SonicWall products are affected by CVE-2025-23006?
The vulnerability affects SMA8200v, SMA6200, SMA6210, SMA7200, SMA7210 (firmware before 12.4.3-02854) and legacy SRA EX6000, EX7000, and EX9000 appliances (firmware at or below 12.4.3-02804). Both the Appliance Management Console and Central Management Console are vulnerable.
Can CVE-2025-23006 be exploited without authentication?
Yes, this is a pre-authentication vulnerability, meaning no credentials are required to exploit it. Any internet-facing SMA1000 management interface running vulnerable firmware is immediately exploitable by any attacker who can reach it over the network.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.