CVE-2025-23006(sonicwall / sma6200)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-02-14. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sma6200
  • sma6200_firmware
  • sma6210
  • sma6210_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
sma6200sma6200_firmwaresma6210sma6210_firmwaresma7200sma7200_firmwaresma7210sma7210_firmwaresma8200vsra_ex6000

1 version affected across 15 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets1 URL
By indicator
Full discourse1 post
  • Dark Web Intelligence@DailyDarkWeb

    🚨 SONICWALL PATCHES CVSS 10.0 UNAUTHENTICATED SSRF IN SMA1000 REMOTE-ACCESS GATEWAYS (CVE-2026-102255) SonicWall released platform hotfixes on October 6, 2026 for a maximum-severity server-side request forgery flaw in its SMA1000 secure remote access appliances. • CVE: CVE-2026-102255 (advisory SNWLID-2026-0017), CVSS 3.0 10.0 • Affected: Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v running 12.4.3-03526 or 12.5.0-02952 platform-hotfix and older • Fixed: 12.4.3-03670 and 12.5.0-03082 platform-hotfix or later • Impact: a remote, unauthenticated attacker could make the appliance send requests on their behalf, reach internal functionality and perform unauthorized operations • Same advisory: three post-auth flaws (CVE-2026-102256 RCE, CVE-2026-102257 Zip Slip, CVE-2026-102258 stored XSS) • Not affected: SMA 100 series and SSL-VPN on SonicWall firewalls ⚠️ Analyst Note: SonicWall says there is no evidence of exploitation in the wild, and the CVE is not in CISA KEV at handoff. SMA1000 appliances have been exploited as zero-days before (CVE-2025-23006 in January 2025), so treat this as a priority patch for any internet-facing appliance. Official: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017 #DDW #DarkWeb #CyberSecurity #SonicWall #CVE #PatchNow

    030205.9K
    207.3K followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
HWsonicwallsma6200---
OSsonicwallsma6200_firmware---
HWsonicwallsma6210---
OSsonicwallsma6210_firmware---
HWsonicwallsma7200---
OSsonicwallsma7200_firmware---
HWsonicwallsma7210---
OSsonicwallsma7210_firmware---
Appsonicwallsma8200v---
HWsonicwallsra_ex6000---
OSsonicwallsra_ex6000_firmware---
HWsonicwallsra_ex7000---
OSsonicwallsra_ex7000_firmware---
HWsonicwallsra_ex9000---
OSsonicwallsra_ex9000_firmware---

Explore more