logo

SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix

ID: 3793d411-e9d8-5169-819b-a2a2cc0a25b3

STIX ID: report--3793d411-e9d8-5169-819b-a2a2cc0a25b3

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-01-23

Date Updated: 2026-04-26

Author: Connor Jones

...
...

SonicWall disclosed a critical CVE-2025-23006 vulnerability in SMA 1000 management consoles enabling remote unauthenticated OS command execution (CVSS 9.8); a platform hotfix (12.4.3-02854) and access-restriction workarounds are available, and Microsoft Threat Intelligence Center is credited with discovery amid concern the flaw may have been exploited as a zero-day.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.