At a glance: SonicWall confirmed active exploitation of CVE-2025-40602, a local privilege escalation vulnerability affecting SMA 1000 series appliances, which was used as part of a vulnerability chain to achieve unauthenticated remote code execution. Organizations should apply available hotfixes and restrict public access to management interfaces and SSH.
Threat summary
On December 17, SonicWall released fixes for CVE‑2025‑40602, a local privilege escalation vulnerability affecting Secure Mobile Access (SMA) 1000 appliances. The flaw was discovered by researchers from Google's Threat Intelligence Group and was exploited as a zero-day prior to the release of a patch. SonicWall confirmed active exploitation but did not attribute the activity to a specific threat actor.
SonicWall addressed the vulnerability in platform hotfix versions 12.4.3-03245 and 12.5.0-02283. CVE‑2025‑40602 has a CVSS score of 6.6.
SMA 1000 appliances provide secure remote access for employees, contractors, and other users connecting to corporate resources. The platform is commonly deployed in enterprise environments to support SSL VPN access and remote workforce connectivity.
The vulnerability exists in the Appliance Management Console (AMC), where insufficient authorization controls can allow a local user to escalate privileges. While CVE‑2025‑40602 alone requires prior access to the appliance, SonicWall reported that it was leveraged in conjunction with CVE‑2025‑23006, a critical deserialization vulnerability affecting the SMA 1000 Appliance Management Console (AMC) and Central Management Console (CMC).
CVE‑2025‑23006 carries a CVSS score of 9.8 and can allow unauthenticated remote command execution. Chaining the two vulnerabilities enabled attackers to achieve remote code execution with root privileges and fully compromise affected appliances.
Insights & mitigations
The exploitation of CVE‑2025‑40602 demonstrates how seemingly lower-severity vulnerabilities can become critical when combined with other flaws. Organizations operating internet-facing SMA 1000 appliances face the greatest risk because CVE‑2025‑23006 provides an entry point that can be combined with CVE‑2025‑40602 to obtain elevated privileges on the device. Organizations should ensure they have applied both the January 2025 fixes for CVE‑2025‑23006 and the December 2025 hotfixes for CVE‑2025‑40602.
MSPs and organizations with multi-tenant environments should verify that all SMA 1000 appliances have been updated to the latest platform hotfixes. Additional mitigations include restricting access to the Appliance Management Console and Central Management Console to trusted administrative networks, disabling management access from the public internet, limiting SSH access to approved administrators, and placing management interfaces behind VPN access or IP-based access controls.
Field Effect MDR users were alerted via ARO earlier this year about devices vulnerable to CVE‑2025‑23006.
For threats such as CVE‑2025‑40602, Field Effect MDR continuously monitors endpoints, networks, and cloud services for activity associated with exploitation attempts targeting remote access infrastructure. Where malicious activity is detected, Field Effect MDR helps contain threats through actions such as isolating affected systems, blocking malicious communications, and disrupting attacker access before compromise can spread further into the environment.
Field Effect's security intelligence team combines business context with threat intelligence to provide vulnerability analysis tailored to each client environment. This helps organizations identify exposed systems, prioritize remediation efforts, and reduce the risk posed by vulnerabilities affecting critical remote access infrastructure.