logo

Critical Vulnerability in SonicWall Secure Mobile Access (SMA) 1000 Series Appliances

ID: eb9aae1d-2caf-5c4e-9433-b6a06ef75633

STIX ID: report--eb9aae1d-2caf-5c4e-9433-b6a06ef75633

Feed Name: Kudelski Security

Threat Score
80/100

Date Published: 2025-01-29

Date Updated: 2026-07-22

...
...

Critical RCE vulnerability (CVE-2025-23006) in SonicWall SMA 1000 Series appliances due to pre-authentication deserialization in AMC/CMC allows unauthenticated attackers to execute arbitrary OS commands; affected systems (SMA6200/6210/7200/7210/8200v, EX6000/7000/9000) running 12.4.3-02804 and earlier should be patched to 12.4.302854 immediately, and if patching is delayed administrative console access (TCP 8443) should be restricted to trusted internal networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.