CVE-2025-40602
SonicWall SMA1000 Missing Authorization Vulnerability
Description
CVE-2025-40602 is a medium-severity local privilege escalation vulnerability (CVSS 6.6) in the SonicWall SMA1000 appliance management console (AMC). The flaw stems from insufficient authorization controls that allow an authenticated administrator to escalate privileges beyond their intended access level. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of December 24, 2025, and has an EPSS score of 0.00309 (53.7th percentile). Ransomware association is currently unknown, and multiple SonicWall SMA appliance models are affected.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| sonicwall | sma6200 firmware | < 12.4.3-03245; >= 12.5.0, < 12.5.0-02283 |
| sonicwall | sma6210 firmware | < 12.4.3-03245; >= 12.5.0, < 12.5.0-02283 |
| sonicwall | sma7200 firmware | < 12.4.3-03245; >= 12.5.0, < 12.5.0-02283 |
| sonicwall | sma7210 firmware | < 12.4.3-03245; >= 12.5.0, < 12.5.0-02283 |
| sonicwall | sma8200v | < 12.4.3-03245; >= 12.5.0, < 12.5.0-02283 |
References
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602(US Government Resource)
Weakness Type
CWE-250: Execution with Unnecessary Privileges
CWE-250 describes situations where software operates with privilege levels higher than necessary, which can amplify the impact of other vulnerabilities. In CVE-2025-40602, the SMA1000 management console grants more privileges than required for certain administrative operations, enabling privilege escalation beyond the intended access boundaries.
CWE-862: Missing Authorization
CWE-862 describes vulnerabilities where software does not perform proper authorization checks when an actor attempts to access a resource or perform an action. In CVE-2025-40602, the SMA1000 appliance management console fails to properly verify that an authenticated administrator is authorized to perform certain privileged operations, allowing them to escalate their access beyond the intended scope of their role.
Impact Analysis
The business impact of CVE-2025-40602 is moderated by the requirement for both network access and high-level administrative credentials, but remains significant given the critical role of SMA1000 appliances in enterprise remote access infrastructure. Confidentiality is highly impacted because a privilege-escalated administrator can access all configurations, certificates, VPN session data, and potentially cached credentials across the SMA1000 deployment. Integrity is highly impacted as the escalated privileges allow modification of security policies, VPN configurations, authentication settings, and firmware — changes that could weaken the entire remote access security posture. Availability is highly impacted because the escalated attacker could disrupt all VPN services, lock out legitimate administrators, or render the appliance inoperable. The EPSS score of 0.00309 (53.7th percentile) is moderate, reflecting that exploitation requires both high-privilege credentials and specific network conditions. However, the KEV listing confirms active exploitation in the wild, indicating that threat actors are successfully chaining this vulnerability with credential theft or other access techniques to compromise SMA1000 deployments. SonicWall SMA appliances are high-value targets because they control remote access for entire organizations, and their compromise can provide attackers with the ability to intercept or manipulate all remote user sessions.
Exploit Maturity
CVE-2025-40602 is confirmed as actively exploited and listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of December 24, 2025, which has already passed. The EPSS score of 0.00309 (53.7th percentile) is relatively moderate, likely reflecting the high prerequisites for exploitation (administrative credentials and network access to the management console). SonicWall has published a PSIRT advisory with remediation details. While no public proof-of-concept exploit code has been tagged in the references, the KEV listing confirms that threat actors have successfully exploited this vulnerability in real-world attacks. SonicWall appliances have been historically targeted by sophisticated threat actors, including ransomware groups, and compromised VPN appliances are frequently used as initial access points in enterprise network breaches. The ransomware association for this specific CVE is listed as unknown, but the broader pattern of SonicWall exploitation by financially motivated actors warrants heightened urgency.
Remediation
- Update SMA1000 firmware to the fixed version — Upgrade to firmware version 12.4.3-03245 or later for the 12.4.x branch, or 12.5.0-02283 or later for the 12.5.x branch. Consult the SonicWall PSIRT advisory for specific firmware download links and upgrade instructions.
- Restrict management console access — Ensure the SMA1000 appliance management console (AMC) is accessible only from a dedicated out-of-band management network, not from the general corporate network or the internet. Use firewall rules to enforce this restriction.
- Audit administrative accounts and activity — Review all administrator accounts on the SMA1000, remove any that are unnecessary, ensure strong unique passwords are in use, and enable multi-factor authentication for management access. Check audit logs for unusual administrative actions that could indicate prior exploitation.
- Implement role-based access control — If the SMA1000 supports granular administrator roles, configure them to follow least-privilege principles, ensuring that administrators have only the specific permissions required for their duties.
- Monitor for SonicWall-specific threat intelligence — Subscribe to SonicWall PSIRT notifications and CISA KEV updates. SonicWall appliances are frequently targeted, and rapid response to future advisories is essential for maintaining security.
Technical Details
The CVSS v3.1 vector for CVE-2025-40602 is AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H, yielding a base score of 6.6 (Medium). Attack Vector (Network) means the vulnerability is exploitable remotely through the SMA1000 management console. Attack Complexity (High) indicates that exploitation requires specific conditions to be met beyond the attacker's direct control, such as particular configuration states or timing conditions, making the attack less reliable than low-complexity vulnerabilities. Privileges Required (High) is a significant mitigating factor — the attacker must already possess administrative-level credentials for the SMA1000, substantially narrowing the pool of potential attackers. User Interaction (None) means no action from another user is required. Scope (Unchanged) indicates the impact remains within the SMA1000's security boundary. Confidentiality, Integrity, and Availability are all High, reflecting that successful exploitation grants the attacker complete control over the appliance. The vulnerability resides in the SMA1000 Appliance Management Console, where certain administrative operations do not properly enforce authorization boundaries. An authenticated administrator can leverage the insufficient authorization checks to perform operations beyond their intended privilege level, effectively gaining unrestricted root-level access to the appliance. The affected SonicWall models include SMA 6200, SMA 6210, SMA 7200, SMA 7210, and SMA 8200v, across both the 12.4.x and 12.5.x firmware branches.
Frequently Asked Questions
Which SonicWall models are affected by CVE-2025-40602?
The vulnerability affects SonicWall SMA 6200, SMA 6210, SMA 7200, SMA 7210, and SMA 8200v appliances running firmware versions prior to 12.4.3-03245 (for the 12.4.x branch) or prior to 12.5.0-02283 (for the 12.5.x branch).
Does the attacker need to be an administrator to exploit this?
Yes, the attacker must already have high-level administrative credentials for the SMA1000 management console. This significantly raises the barrier to exploitation but does not eliminate the risk, as administrative credentials can be obtained through phishing, credential stuffing, or prior breaches.
Has the CISA remediation deadline already passed?
Yes, the KEV remediation deadline was December 24, 2025. Organizations that have not yet patched should treat this as an urgent priority and investigate for potential signs of compromise.
Why is a privilege escalation from admin to higher access significant?
Even within administrative roles, properly configured systems enforce boundaries on what different administrators can do. A privilege escalation vulnerability allows an attacker with limited administrative access to gain unrestricted control, potentially bypassing audit controls, accessing cryptographic keys, or modifying the appliance's firmware — actions that are normally restricted even from standard administrators.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.