๐Ÿ” CVE Alert

CVE-2025-23006

CRITICAL 9.8 โš ๏ธ CISA KEV
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CWE CWE-502
Vendor sonicwall
Product sma1000
Published Jan 23, 2025
Last Updated Feb 26, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for sonicwall sma1000

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2025-23006.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SonicWall / SMA1000
12.4.3-02804 (platform-hotfix) and earlier versions.

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
psirt.global.sonicwall.com: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-23006