Sonicwall
Sonicwall Sma7200 Firmware: vulnerabilidades y CVE
Sonicwall Sma7200 Firmware tiene 6 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses5
Críticas1
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-40602 | Media (6.6) | 2.8% | ⚠ Explotación activa | 18 dic 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
| CVE-2025-23006 | Crítica (9.8) | 23% | ⚠ Explotación activa | 23 ene 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-4116 | Alta (7.2) | 0.71% | — | 9 abr 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication. |
| CVE-2026-4114 | Media (6.6) | 0.74% | — | 9 abr 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication. |
| CVE-2026-4113 | Alta (7.2) | 0.60% | — | 9 abr 2026 | An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials. |
| CVE-2026-4112 | Alta (7.2) | 0.53% | — | 9 abr 2026 | Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate… |
| CVE-2025-40602 | Media (6.6) | 2.8% | ⚠ Explotación activa | 18 dic 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
| CVE-2025-23006 | Crítica (9.8) | 23% | ⚠ Explotación activa | 23 ene 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could… |