CVE-2025-40602

SonicWall SMA1000

Published 18 Dec 2025 · updated 17 Jun 2026 · Analyzed

6.6 Medium · CVSS 3.1, CISA ADP

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 17 Dec 2025, with a remediation deadline of 24 Dec 2025 for US federal agencies.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable

Description

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

References