CVE-2025-40602 is a local privilege escalation vulnerability found in the management console of SonicWall SMA1000 appliances, specifically affecting models like SMA6200, SMA7200, and SMA8200v. This vulnerability, rated Medium with a CVSS score of 6.6, stems from insufficient authorization (CWE-250, CWE-862) and allows a highly privileged attacker to achieve full compromise of confidentiality, integrity, and availability. Critically, this CVE is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog, and has garnered significant community discussion and media coverage despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.4.3-03245CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:* | ||
>= 12.5.0, < 12.5.0-02283CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:* | ||
< 12.4.3-03245CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:* | ||
>= 12.5.0, < 12.5.0-02283CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:* | ||
< 12.4.3-03245CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.