As outlined in The Hacker News, SonicWall has released patches for a critical security flaw affecting its Secure Mobile Access (SMA) 100 series appliances. This vulnerability, identified as CVE-2025-40602, has been actively exploited in real-world attacks.
The flaw is a local privilege escalation issue stemming from insufficient authorization within the appliance management console. It impacts specific versions of the SMA 100 series, with fixes available in newer platform-hotfix releases. SonicWall noted that this vulnerability was reportedly used in conjunction with CVE-2025-23006, a previously patched flaw, to achieve unauthenticated remote code execution with root privileges. Google Threat Intelligence Group researchers Clément Lecigne and Zander Work are credited with discovering CVE-2025-40602. Details regarding the scope and perpetrators of the attacks remain limited, though past campaigns have targeted end-of-life SonicWall devices.
The active exploitation of this vulnerability underscores the critical importance of timely patching for network security appliances. Organizations utilizing SonicWall SMA 100 series devices are strongly advised to apply the provided updates immediately to mitigate the risk of compromise.
Source: The Hacker News
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
