« Back to list

Sonicwall

Sonicwall Sma7200 Firmware: vulnerabilities and CVEs

Sonicwall Sma7200 Firmware has 6 published vulnerabilities, 5 of them in the last 12 months. 1 are rated critical and 2 are listed by CISA as actively exploited.

CVEs6
Last 12 months5
Critical1
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-40602Medium (6.6)2.8%⚠ Active exploitationDec 18, 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
CVE-2025-23006Critical (9.8)23%⚠ Active exploitationJan 23, 2025
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-4116High (7.2)0.71%—Apr 9, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
CVE-2026-4114Medium (6.6)0.74%—Apr 9, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
CVE-2026-4113High (7.2)0.60%—Apr 9, 2026
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
CVE-2026-4112High (7.2)0.53%—Apr 9, 2026
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate…
CVE-2025-40602Medium (6.6)2.8%⚠ Active exploitationDec 18, 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
CVE-2025-23006Critical (9.8)23%⚠ Active exploitationJan 23, 2025
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could…

Other products by Sonicwall