CORRECTION: It was originally reported that the security flaw affected a different series of Secure Mobile Access appliances.As outlined in The Hacker News, SonicWall has released patches for a critical security flaw affecting its Secure Mobile Access (SMA) 1000 series appliances. This vulnerability, identified as CVE-2025-40602, has been actively exploited in real-world attacks.The flaw is a local privilege escalation issue stemming from insufficient authorization within the appliance management console. It impacts specific versions of the SMA 1000 series, with fixes available in newer platform-hotfix releases. SonicWall noted that this vulnerability was reportedly used in conjunction with CVE-2025-23006, a previously patched flaw, to achieve unauthenticated remote code execution with root privileges. Google Threat Intelligence Group researchers Clément Lecigne and Zander Work are credited with discovering CVE-2025-40602. Details regarding the scope and perpetrators of the attacks remain limited, though past campaigns have targeted end-of-life SonicWall devices.The active exploitation of this vulnerability underscores the critical importance of timely patching for network security appliances. Organizations utilizing SonicWall SMA 1000 series devices are strongly advised to apply the provided updates immediately to mitigate the risk of compromise.Source: The Hacker News
Network Security, Vulnerability Management, Patch/Configuration Management
SonicWall SMA 1000 Series vulnerability actively exploited
(Credit: monticellllo – stock.adobe.com)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
