Medium severity6.6CISA KEVNVD Advisory· Published Dec 18, 2025· Updated Jun 17, 2026
CVE-2025-40602
CVE-2025-40602
Description
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Affected products
7cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*range: <12.4.3-03245
- cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*range: <12.4.3-03245
Patches
Vulnerability mechanics
References
2- psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
3- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildTenable Blog · Jul 15, 2026
- Top 10 Best Unified Threat Management (UTM) Solutions in 2026Cyber Security News · Jul 10, 2026
- Top 10 Best Next-Generation Firewall (NGFW) Solutions in 2026Cyber Security News · Jul 6, 2026