When chained together, CVE-2025-40602 and CVE-2025-23006 could lead to unauthenticated remote code execution with root privileges
When chained together, CVE-2025-40602 and CVE-2025-23006 could lead to unauthenticated remote code execution with root privileges
The following platforms are known to be affected:
SonicWall Secure Mobile Access (SMA) 1000 Series
CVE-2025-40602 Under Active Exploitation
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-40602 to their Known Exploited Vulnerabilities (KEV) Catalog.
When chained together, CVE-2025-40602 and CVE-2025-23006 could lead to unauthenticated remote code execution with root privileges.
The NHS England National CSOC has previously published a High Severity Cyber Alert ( CC-4609 ) addressing CVE-2025-23006. NHS England National CSOC assesses future exploitation as likely.
SonicWall has released a security advisory to address a vulnerability in SonicWall SMA1000 Appliance Management Console (AMC).
When chained together, CVE-2025-40602 and CVE-2025-23006 could lead to unauthenticated remote code execution with root privileges.
Note : SonicWall Firewall products are not affected by this vulnerability.
Affected organisations are encouraged to review SonicWall's security advisory and apply the relevant updates as soon as possible.
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Last edited: 18 December 2025 1:35 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
