EXPOSURES › CVE-2025-40602
CVE-2025-40602
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatched
SonicWall SMA1000 exposed to unpatched AMC privilege escalation
SonicWall's SMA1000 appliances had an unpatched vulnerability in their management console allowing for privilege escalation, exploited before patching
Shame score — Systemic weakness in security engineering and patch management leading to multiple actively exploited vulnerabilities
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.