CVE-2025-40602

MEDIUM KEV RANSOMWARE

Sonicwall Sma6200 Firmware < 12.4.3-03245 - Privilege Escalation

Title source: rule

Description

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Exploits (2)

nomisec WRITEUP 3 stars
by rxerium · poc
https://github.com/rxerium/CVE-2025-40602
nomisec WRITEUP 1 stars
by cyberleelawat · poc
https://github.com/cyberleelawat/CVE-2025-40602

Scores

CVSS v3 6.6
EPSS 0.0031
EPSS Percentile 53.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2025-12-17
VulnCheck KEV 2025-12-17
ENISA EUVD EUVD-2025-204255
Ransomware Use Confirmed

Classification

CWE
CWE-862 CWE-250
Status published

Affected Products (5)

sonicwall/sma6200_firmware < 12.4.3-03245
sonicwall/sma6210_firmware < 12.4.3-03245
sonicwall/sma7200_firmware < 12.4.3-03245
sonicwall/sma7210_firmware < 12.4.3-03245
sonicwall/sma8200v < 12.4.3-03245

Timeline

Published Dec 18, 2025
KEV Added Dec 17, 2025
Tracked Since Feb 18, 2026