SonicWall warns of SMA1000 RCE flaw exploited in zero-day attacks
ID: b9e8f519-c416-58b3-93cb-323ad84aa48d
STIX ID: report--b9e8f519-c416-58b3-93cb-323ad84aa48d
Feed Name: Bleeping Computer
Threat Score
SonicWall disclosed a critical pre-authentication deserialization vulnerability (CVE-2025-23006, CVSS 9.8) in SMA1000 Appliance Management Console and Central Management Console that has been reported exploited as a zero-day; administrators are urged to apply the platform-hotfix (12.4.3-02854 and later) immediately, as thousands of devices are exposed online and active exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
