Sonicwall warns of new SMA1000 zero-day exploited in attacks
ID: ecc9d364-f555-549b-ac16-540aa1d24999
STIX ID: report--ecc9d364-f555-549b-ac16-540aa1d24999
Feed Name: Bleeping Computer
Threat Score
SonicWall warned of an actively exploited zero-day chain against SMA1000 appliances that chains a medium-severity local privilege escalation (CVE-2025-40602) with a critical pre-auth deserialization RCE (CVE-2025-23006, CVSS 9.8) to achieve root-level remote code execution; vendors have released hotfixes and over 950 exposed devices remain visible online, raising significant risk to organizations using these remote-access gateways.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
