PoC Index

CVE-2025-40602

KEVMEDIUM 6.6EPSS 2.1%

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

CVSS v3.1
6.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
2.11% chance of exploitation in the next 30 days, 81th percentile
CISA KEV
added 2025-12-17
Published
2025-12-18

Proof-of-concept exploits (1)

References

Related