logo

SonicWall Edge Access Devices Hit by Zero-Day Attacks

ID: b6daa324-67aa-545d-b362-bc7f78fab2e9

STIX ID: report--b6daa324-67aa-545d-b362-bc7f78fab2e9

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Rob Wright

...
...

SonicWall disclosed a zero-day LPE, CVE-2025-40602 (CVSS 6.6), which has been observed in chained attacks alongside an older critical flaw CVE-2025-23006 (CVSS 9.8); the vendor released hotfixes (12.4.3-03245+, 12.5.0-02283+) and recommended restricting AMC/SSH access or disabling the SSL VPN management interface, while noting prior customer-impacting incidents including a cloud backup data breach and ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.