Description

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

INFO

Published Date :

2025-01-23T11:37:41.148Z

Last Modified :

2026-02-26T19:08:57.752Z

Source :

sonicwall
AFFECTED PRODUCTS

The following products are affected by CVE-2025-23006 vulnerability.

Vendors Products
Sonicwall
  • Sma6200
  • Sma6200 Firmware
  • Sma6210
  • Sma6210 Firmware
  • Sma7200
  • Sma7200 Firmware
  • Sma7210
  • Sma7210 Firmware
  • Sma8200v
  • Sra Ex6000
  • Sra Ex6000 Firmware
  • Sra Ex7000
  • Sra Ex7000 Firmware
  • Sra Ex9000
  • Sra Ex9000 Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-23006.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact