CVE-2025-23006

SonicWall SMA1000 Appliances: Deserialization

As of , CVE-2025-23006 in SonicWall SMA1000 Appliances is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 24 January 2025
US federal deadline
14 February 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
KnownCISA changed it from Unknown to Known on 12 May 2025.
EPSS score
0.23Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.00 on 24 January 2025EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: psirt.global.sonicwall.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

CISA's description

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

The CVE record's description, from sonicwall

CVE published
23 January 2025
Assigned by
sonicwall
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-502
Deserialization of Untrusted Data
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Ransomware use: Unknown to Known.

SMA1000 Appliances: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-83548Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.09
CVE-2026-83549OS Command InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.11
CVE-2026-15409Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module0.07
CVE-2026-15410Code InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year0.12

Read further