SonicWall Edge Access Devices Hit by Zero-Day Attacks
ID: b6daa324-67aa-545d-b362-bc7f78fab2e9
STIX ID: report--b6daa324-67aa-545d-b362-bc7f78fab2e9
Feed Name: Dark Reading
Threat Score
SonicWall disclosed a zero-day LPE, CVE-2025-40602 (CVSS 6.6), which has been observed in chained attacks alongside an older critical flaw CVE-2025-23006 (CVSS 9.8); the vendor released hotfixes (12.4.3-03245+, 12.5.0-02283+) and recommended restricting AMC/SSH access or disabling the SSL VPN management interface, while noting prior customer-impacting incidents including a cloud backup data breach and ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
