CVE-2025-40602

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*

History

19 Dec 2025, 13:57

Type Values Removed Values Added
First Time Sonicwall sma7210 Firmware
Sonicwall sma7200 Firmware
Sonicwall sma7210
Sonicwall sma7200
Sonicwall sma6210 Firmware
Sonicwall sma8200v
Sonicwall sma6200
Sonicwall
Sonicwall sma6210
Sonicwall sma6200 Firmware
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019 - Vendor Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602 - US Government Resource
CPE cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:*

18 Dec 2025, 12:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.6

18 Dec 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 11:15

Updated : 2025-12-19 13:57


NVD link : CVE-2025-40602

Mitre link : CVE-2025-40602

CVE.ORG link : CVE-2025-40602


JSON object : View

Products Affected

sonicwall

  • sma6210_firmware
  • sma7200
  • sma7210_firmware
  • sma6200_firmware
  • sma8200v
  • sma6210
  • sma7200_firmware
  • sma6200
  • sma7210
CWE
CWE-250

Execution with Unnecessary Privileges

CWE-862

Missing Authorization