LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2025-23006

CVE-2025-23006

SonicWall SMA1000 Appliances Deserialization Vulnerability

CVSS 9.8 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED RANSOMWARE
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2025-01-24. Federal remediation due 2025-02-14.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Summary

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CVSS 3.1 breakdown

Base score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Sonicwall sma8200vSonicwall sma6200 firmwareSonicwall sma6200Sonicwall sma6210 firmwareSonicwall sma6210Sonicwall sma7200 firmwareSonicwall sma7200Sonicwall sma7210 firmwareSonicwall sma7210Sonicwall sra ex6000 firmwareSonicwall sra ex6000Sonicwall sra ex7000 firmwareSonicwall sra ex7000Sonicwall sra ex9000 firmwareSonicwall sra ex9000
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-31. Always verify against the vendor advisory before acting.

Scroll to Top