Zero-day vulnerability in SonicWall SMA 1000

Missing authorization
CVE-2025-40602

Vulnerability details

Advisory: SB2025121748 - Privilege escalation in SonicWall SMA1000

Vulnerable component: SonicWall SMA 1000

CVE-ID: CVE-2025-40602

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-862 - Missing Authorization

Description:

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to missing authorization checks in the appliance management console (AMC). A remote authenticated user can obtain root privileges on the system.

Note, the vulnerability was used in the wild along with #VU103262 (CVE-2025-23006) to achieve remote unauthenticated code execution with root privileges. 

External links:

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019