Another bad week for SonicWall as SMA 1000 zero-day under active exploit
ID: 2f966faf-71d1-513d-9375-a90eee776d4e
STIX ID: report--2f966faf-71d1-513d-9375-a90eee776d4e
Feed Name: The Register (Security)
SonicWall has warned of an actively exploited zero-day (CVE-2025-40602) in SMA 1000 appliance management consoles that allows authenticated attackers to escalate privileges; it has been chained with CVE-2025-23006 to achieve unauthenticated root remote code execution. Customers are urged to apply hotfixes immediately and restrict Appliance Management Console access, as hundreds of SMA 1000 units are visible on the internet; the advisory also recalls a prior MySonicWall backup breach that exposed configuration files and was attributed to state-sponsored actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
