{"id":"CVE-2025-23006","title":"Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…","summary":"Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"sonicwall","product":"sma8200v","affected":["sma8200v < 12.4.3-02854","sma6200_firmware < 12.4.3-02854","sma6210_firmware < 12.4.3-02854","sma7200_firmware < 12.4.3-02854","sma7210_firmware < 12.4.3-02854","sra_ex6000_firmware <= 12.4.3-02804","sra_ex7000_firmware <= 12.4.3-02804","sra_ex9000_firmware <= 12.4.3-02804"],"patched":["sma8200v 12.4.3-02854","sma6200_firmware 12.4.3-02854","sma6210_firmware 12.4.3-02854","sma7200_firmware 12.4.3-02854","sma7210_firmware 12.4.3-02854"],"published":"2025-01-23","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-23006","references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002","label":"PSIRT@sonicwall.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-23006","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.23432,"epssPercentile":0.9773,"kev":true,"kevDateAdded":"2025-01-24","kevDueDate":"2025-02-14","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-04T05:36:12.871Z","slug":"CVE-2025-23006","body":"## Overview\n\nPre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.\n\n## Affected\n\n- `sma8200v < 12.4.3-02854`\n- `sma6200_firmware < 12.4.3-02854`\n- `sma6210_firmware < 12.4.3-02854`\n- `sma7200_firmware < 12.4.3-02854`\n- `sma7210_firmware < 12.4.3-02854`\n- `sra_ex6000_firmware <= 12.4.3-02804`\n- `sra_ex7000_firmware <= 12.4.3-02804`\n- `sra_ex9000_firmware <= 12.4.3-02804`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sma8200v 12.4.3-02854`\n- `sma6200_firmware 12.4.3-02854`\n- `sma6210_firmware 12.4.3-02854`\n- `sma7200_firmware 12.4.3-02854`\n- `sma7210_firmware 12.4.3-02854`","depth":"hadal","depthScore":89,"depthScoreParts":{"impact":53.9,"likelihood":4.7,"exploitation":25,"ransomware":5},"changes":[]}