SonicWall Security Update – 23 January 2025

SonicWall has released a security update to fix a critical vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) version 12.4.3-02804 and earlier versions.

The addressed vulnerability could allow the remote unauthenticated attacker to execute arbitrary OS commands and gain unauthorized access to the affected systems.

SonicWALL SMA1000 Pre-Authentication Remote Command Execution Vulnerability (CVE-2025-23006):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2025-23006

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SonicWall Security Advisory

References