Hackers Exploiting SonicWall SMA1000 0-day Vulnerability to Escalate Privileges
ID: e241278d-9936-53d5-a711-24cad7f440db
STIX ID: report--e241278d-9936-53d5-a711-24cad7f440db
Feed Name: cybersecurityNews.com
Security researchers and SonicWall PSIRT disclosed CVE-2025-40602, a privilege-escalation vulnerability in the SonicWall SMA1000 management console that is actively exploited; when chained with CVE-2025-23006 (unauthenticated RCE), attackers can achieve root-level remote code execution on affected appliances. SonicWall published affected and fixed versions and recommends immediate patching plus temporary mitigations (restrict SSH to VPN/allowed IPs and disable public management access).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
