VendorsSonicWallsma6200_firmwareall versions
Vulnerabilities

SonicWall SMA6200 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-23006
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Published 2025-01-23 · Analyzed
9.8KEVEPSS 0.234
CVE-2026-4116
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
Published 2026-04-09 · Analyzed
7.2EPSS 0.007
CVE-2026-4113
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
Published 2026-04-09 · Analyzed
7.2EPSS 0.006
CVE-2026-4112
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
Published 2026-04-09 · Analyzed
7.2EPSS 0.005
CVE-2025-40602
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Published 2025-12-18 · Analyzed
6.6KEVEPSS 0.028
CVE-2026-4114
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
Published 2026-04-09 · Analyzed
6.6EPSS 0.007