CVE-2025-40602
Last modified
CVE-2025-40602 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).. CISA has confirmed active exploitation in the wild. EPSS estimates a 1.91% chance of exploitation in the next 30 days.
Description
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Sma6200 Firmware | < 12.4.3-03245 |
| Sonicwall | Sma6200 Firmware | >= 12.5.0, < 12.5.0-02283 |
| Sonicwall | Sma6210 Firmware | < 12.4.3-03245 |
| Sonicwall | Sma6210 Firmware | >= 12.5.0, < 12.5.0-02283 |
| Sonicwall | Sma7200 Firmware | < 12.4.3-03245 |
| Sonicwall | Sma7200 Firmware | >= 12.5.0, < 12.5.0-02283 |
| Sonicwall | Sma7210 Firmware | < 12.4.3-03245 |
| Sonicwall | Sma7210 Firmware | >= 12.5.0, < 12.5.0-02283 |
| Sonicwall | Sma8200v | < 12.4.3-03245 |
| Sonicwall | Sma8200v | >= 12.5.0, < 12.5.0-02283 |
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-40602?
How severe is CVE-2025-40602?
How do I fix CVE-2025-40602?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40597A Heap-based buffer overflow vulnerability in the SMA100 ser…7.5
- CVE-2025-40598A Reflected cross-site scripting (XSS) vulnerability exists …6.1
- CVE-2025-40599An authenticated arbitrary file upload vulnerability exists …9.1
- CVE-2025-4060A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-40600Use of Externally-Controlled Format String vulnerability in …9.8
- CVE-2025-40601A Stack-based buffer overflow vulnerability in the SonicOS S…7.5
- CVE-2025-40603A potential exposure of sensitive information in log files i…4.5
- CVE-2025-40604Download of Code Without Integrity Check Vulnerability in th…9.8
- CVE-2025-40605A Path Traversal vulnerability has been identified in the Em…5.3
- CVE-2025-4061A vulnerability, which was classified as critical, was found…7.8
- CVE-2025-40615Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy…6.1
- CVE-2025-40616Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy…6.1
Are you affected by CVE-2025-40602?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
