Target Industry
Indiscriminate, opportunistic targeting.
Overview
SonicWall has released a hotfix patch for a critical vulnerability with the products in the Secure Mobile Access (SMT) 1000 series – specifically the Appliance Management Console (AMC) and Central Management Console (CMC). These products allow employees to access corporate networks via a VPN. This Critical vulnerability, identified as CVE- 2025-23006 (CVSS4.0 9.8), allows attackers to remotely execute arbitrary operating system commands.
Impact
If this vulnerability is successfully exploited, an attacker could remotely execute arbitrary OS commands on the affected system. This can lead to the hacker gaining full control over the system as well as access to sensitive data and service disruption.
Vulnerability Detection
- Version 12.4.3-02854 has addressed this issue and patched
- Version 12.4.3-02804 (platform-hotfix) and earlier versions are vulnerable
Exploitation
There is not a proof of concept for CVE- 2025-23006 yet but users of these products have already reported zero-day attacks to SonicWall.
Containment, Mitigations & Remediations
- A patch has been released that remediates this vulnerability
- To find the latest version, visit SonicWall’s SMA 1000 webpage and make sure AMC and CMC are updated.
Indicators of Compromise
No indicators of compromise (IoCs) are available currently.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Threat Landscape
SonicWall products, including SMA 1000 series, are widely deployed in enterprise environments across various sectors, including government, healthcare, financial services, energy, and education. These solutions enable secure remote access and support for zero-trust access frameworks, making them high-value targets for cybercriminals.
TTPs
Based on current released information:












