THREAT OPS › CVEs › CVE-2025-23006
CVE-2025-23006 — SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
Vulnerability details
- Affected productsSMA1000 Appliances
- KEV remediation due2025-02-14
Related reporting
- [NVD] CVE-2025-23006 (CRITICAL 9.8) — Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrnvd
- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildtenable