Junglewise Threat Intelligence

CVE-2025-40602: SonicWall SMA1000 privilege escalation in AMC

CVE-2025-40602 · Severity: critical · CVSS 6.6 · Exploited in the wild · Published 2025-12-17

Executive brief

A security flaw in SonicWall SMA 1000 series remote access appliances could allow an attacker to gain higher-level administrative control over the device. This appliance is typically used to provide secure remote access to corporate networks; an exploit could allow an attacker to modify system settings or disrupt secure connections. This vulnerability has been reported as being actively exploited in the wild.

Technical details

A missing authorization vulnerability (CWE-862) and execution with unnecessary privileges (CWE-250) exists in the SonicWall SMA1000 Appliance Management Console (AMC). The flaw allows an authenticated user with high privileges to escalate their permissions further within the management interface. While the NVD description notes it as 'local privilege escalation,' the CISA-ADP CVSS vector indicates a network attack vector with high complexity and high privileges required. This vulnerability is listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Patches are available in firmware versions 12.4.3-03245 and 12.5.0-02283.

Affected products

  • SonicWall SMA 1000 Series Firmware Versions up to 12.4.3-03245 and 12.5.0 up to 12.5.0-02283
  • SonicWall SMA 8200v Versions up to 12.4.3-03245 and 12.5.0 up to 12.5.0-02283

Timeline

  • 2025-12-17: disclosed
  • 2025-12-17: kev added: Added to CISA KEV catalog due to active exploitation.
  • 2025-12-18: advisory

Related threats