LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-40602: SonicWall SMA1000 Missing Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 17, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-40602 to its Known Exploited Vulnerabilities catalog on Dec 17, 2025, with a federal patch deadline of Dec 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.

SonicWall SMA1000 appliances contain a missing authorization vulnerability that can allow an attacker to escalate privileges within the appliance management console. The issue stems from insufficient authorization checks combined with execution under higher-than-needed privileges, giving an unauthenticated or low-privileged actor access to administrative functions they should not reach.

How it works

The weakness is tracked as CWE-862 (Missing Authorization) and CWE-250 (Execution with Unnecessary Privileges). In this class of flaw, the application fails to verify that a caller possesses the required rights before performing sensitive operations on the management interface. An attacker who reaches the console can therefore invoke administrative actions without completing the normal authorization path.

Am I affected? How to find it in your systems

Inventory every SonicWall SMA1000 appliance that exposes its management console. Confirm the presence of the product, note its network location, and compare the installed build against the vendor advisory for affected configurations. Review authentication and authorization settings in the console itself, paying particular attention to any accounts or integrations that bypass normal role checks.

How to remediate

Apply the vendor-supplied update that addresses the authorization checks. After patching, review all accounts and service integrations to ensure they operate under the principle of least privilege. Disable or restrict any management features that are not required for day-to-day operations.

If you can't patch immediately

Place the management interface behind additional network segmentation so that only authorized jump hosts can reach it. Consider virtual patching or request-filtering controls that block unauthorized administrative calls. If mitigations cannot be applied, follow CISA guidance to discontinue use of the affected appliance until remediation is possible. Increase monitoring of console logs and authentication events for signs of privilege abuse.

If your data may have been exposed

Actively exploited authorization flaws have led to breaches in similar appliances. Run a free exposure scan of your organization’s email addresses against known breach data to determine whether credentials or other identifiers have already appeared in public datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SMA1000 appliance
WeaknessCWE-862
Added to CISA KEVDec 17, 2025
Federal patch deadlineDec 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities