EXPOSURES › CVE-2025-23006
CVE-2025-23006
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSonicWall SMA1000 appliances suffered a deserialization vulnerability allowing remote, unauthenticated attackers to execute arbitrary OS commands.
A deserialization of untrusted data flaw in the SonicWall SMA1000 Management Consoles enabled remote code execution without authentication. This is critical for DIB organizations because it represents a severe, avoidable exposure where attackers could pivot into networks, and it highlights the risk of relying on unpatched or poorly secured network hardware. Organizations must ensure all network appliances are patched and monitored for known KEV vulnerabilities.
Shame score — A critical, actively exploited vulnerability in a widely deployed network security appliance that allowed remote code execution without authentication, indicating severe negligence in patch management and security design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.