Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

SonicWall Patches Exploited SMA 1000 Zero-Day

Posted on December 18, 2025December 18, 2025 By CWS

SonicWall on Wednesday warned that risk actors have been exploiting a vulnerability within the Safe Cell Entry (SMA) 1000 equipment administration console (AMC) as a zero-day.

The newly disclosed flaw, tracked as CVE-2025-40602 (CVSS rating of 6.6), is a medium-severity native privilege escalation challenge.

Rooted in inadequate authorization within the SMA 1000 AMC administration instrument, the bug was found by researchers of Google’s Risk Intelligence Group (GTIG).

In its Wednesday advisory, SonicWall warned that the safety defect has been exploited as a zero-day, however didn’t element the noticed assaults.

“This vulnerability was reported to be leveraged together with CVE-2025-23006 (CVSS rating 9.8) to realize unauthenticated distant code execution with root privileges,” the corporate stated.

Disclosed in January as a zero-day and described as an untrusted knowledge deserialization challenge, CVE-2025-23006 was patched in model 12.4.3-02854 of the SMA 100 sequence platform.

The contemporary SonicWall zero-day was resolved in variations 12.4.3-03245 (platform-hotfix) and 12.5.0-02283 (platform-hotfix).

On Wednesday, the US cybersecurity company CISA added CVE-2025-40602 to its Recognized Exploited Vulnerabilities (KEV) listing, urging quick patching.Commercial. Scroll to proceed studying.

Per Binding Operational Directive (BOD) 22-01, federal businesses have three weeks to handle flaws newly added to KEV, however CISA has given them just one week to resolve the brand new SonicWall zero-day.

Organizations are suggested to replace their SMA 1000 home equipment to the most recent hotfix as quickly as doable, or to use mitigations offered by SonicWall.

These embody proscribing SSH entry to the AMC through VPN or particular admin IPs, and disabling the SSL VPN administration interface (AMC) and SSH entry from the general public web.

In line with SonicWall, the vulnerability doesn’t impression SSL-VPN operating on SonicWall firewall merchandise.

SonicWall disclosed the safety defect on the identical day that Cisco warned of a bug in its safety home equipment that has been exploited as a zero-day by a China-linked risk group.

Associated: SonicWall Patches Excessive-Severity Flaws in Firewalls, E mail Safety Equipment

Associated: State-Sponsored Hackers Stole SonicWall Cloud Backups in Latest Assault

Associated: Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw

Associated: Unpatched Gogs Zero-Day Exploited for Months

Security Week News Tags:Exploited, Patches, SMA, SonicWall, ZeroDay

Post navigation

Previous Post: Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
Next Post: Critical Apache Commons Text Vulnerability Enables Remote Code Execution Attacks

Related Posts

Train Hack Gets Proper Attention After 20 Years: Researcher  Security Week News
Up to 25% of Internet-Exposed ICS Are Honeypots: Researchers Security Week News
Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries Security Week News
Dropzone AI Raises $37 Million for Autonomous SOC Analyst Security Week News
US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack Security Week News
Tight Cybersecurity Budgets Accelerate the Shift to AI-Driven Defense Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark