CVE-2025-40602

MEDIUM CISA KEV EPSS 77.2%
Published Dec 18, 20256mo ago · Modified Jun 17, 20261w ago
6.6 CVSS 3.1
Medium
Find Similar
Published Dec 18, 2025 6mo ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Dec 17, 2025 6mo ago
KEV Due Dec 24, 2025 188d overdue

Description

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

CVSS Details

Base Score
6.6
Exploitability
0.7
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity High
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

CISA Known Exploited Overdue 188d
Added
Dec 17, 2025
Due
Dec 24, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable

EPSS Exploit Probability
77.2% percentile
Exploit & Patch Status
Actively Exploited (KEV)
No Patch Available

Weaknesses 2

CWE-250
CWE-862 Missing Authorization Authorization

Affected Products 14

VendorProductVersionRange
sonicwallsma6200_firmware* <12.4.3-03245
sonicwallsma6200_firmware*≥12.5.0  –  <12.5.0-02283
sonicwallsma6200*any
sonicwallsma6210_firmware* <12.4.3-03245
sonicwallsma6210_firmware*≥12.5.0  –  <12.5.0-02283
sonicwallsma6210*any
sonicwallsma7200_firmware* <12.4.3-03245
sonicwallsma7200_firmware*≥12.5.0  –  <12.5.0-02283
sonicwallsma7200*any
sonicwallsma7210_firmware* <12.4.3-03245
sonicwallsma7210_firmware*≥12.5.0  –  <12.5.0-02283
sonicwallsma7210*any
sonicwallsma8200v* <12.4.3-03245
sonicwallsma8200v*≥12.5.0  –  <12.5.0-02283

References 2

  • psirt.global.sonicwall.com https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019
    Vendor Advisory
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602
    US Government Resource

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.