CVE-2025-23006
Last modified
CVE-2025-23006 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.. CISA has confirmed active exploitation in the wild. EPSS estimates a 23.43% chance of exploitation in the next 30 days.
Description
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Sma8200v | < 12.4.3-02854 |
| Sonicwall | Sma6200 Firmware | < 12.4.3-02854 |
| Sonicwall | Sma6210 Firmware | < 12.4.3-02854 |
| Sonicwall | Sma7200 Firmware | < 12.4.3-02854 |
| Sonicwall | Sma7210 Firmware | < 12.4.3-02854 |
| Sonicwall | Sra Ex6000 Firmware | <= 12.4.3-02804 |
| Sonicwall | Sra Ex7000 Firmware | <= 12.4.3-02804 |
| Sonicwall | Sra Ex9000 Firmware | <= 12.4.3-02804 |
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-23006US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-23006?
How severe is CVE-2025-23006?
How do I fix CVE-2025-23006?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-22992A SQL Injection vulnerability exists in the /feed/insert.jso…9.8
- CVE-2025-22994O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Me…6.1
- CVE-2025-22996A stored cross-site scripting (XSS) vulnerability in the spf…4.8
- CVE-2025-22997A stored cross-site scripting (XSS) vulnerability in the prf…4.8
- CVE-2025-2300Hitachi Ops Center Common Services within Hitachi Ops Center…5.5
- CVE-2025-23001A Host header injection vulnerability exists in CTFd 3.7.5, …6.1
- CVE-2025-23007A vulnerability in the NetExtender Windows client log export…5.5
- CVE-2025-23008An improper privilege management vulnerability in the SonicW…7.2
- CVE-2025-23009A local privilege escalation vulnerability in SonicWall NetE…7.2
- CVE-2025-2301Authorization Bypass Through User-Controlled Key vulnerabili…4.4
- CVE-2025-23010An Improper Link Resolution Before File Access ('Link Follow…7.2
- CVE-2025-23011Fedora Repository 3.8.1 allows path traversal when extractin…8.8
Are you affected by CVE-2025-23006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
