> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Alleged sale of 0-day SonicWall SRA 4600 Preauth RCE
- URL: https://darkwebinformer.com/alleged-sale-of-0-day-sonicwall-sra-4600-preauth-rce/
- Published: 2025-06-09T14:37:58.000Z
- Updated: 2025-09-04T22:21:52.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

× 

## 📢 Unlock Exclusive Cyber Threat Intelligence

Powered by [DarkWebInformer.com](https://darkwebinformer.com/) 

Get foundational access to breach intelligence — track breaches, leaks, and threats in real-time with unfiltered screenshots and expert summaries. 

📚 

**4,000+ Blog Posts:** Continuously updated with breach reports and threat summaries.

📢 

**15,000+ Alerts:** Access detailed breach, leak, and DDoS alerts updated daily.

📤 

**Unredacted Threat Feed:** Track breaches and leaks in real-time with JSON export support.

🔍 

**Leak & Breach Coverage:** Get direct access to verified breach posts and claims.

📡 

**Snippets & Quick Facts:** Receive concise summaries of DDoS, defacements, and breaches.

🤖 

**WhiteIntel.io API Access:** Access an integrated API, in breach blog posts.

🖼️ 

**High-Resolution Images:** View uncompressed, watermark-free breach evidence.

🔑 

**Keyword Notifications:** Receive browser alerts when monitored keywords are triggered.

📧 

**Custom Email Alerts:** Get curated daily, weekly, or filtered alert summaries.

👥 

**Telegram Channels:** Stay in the know with access to different Telegram channels.

📨 

**PGP Contact Details:** Access verified PGPs for ransomware and threat groups.

⚠️ 

**Coming Soon: CVE Alert Feed** – Be first to know when new vulnerabilities emerge.

[💳 Subscribe Now](https://darkwebinformer.com/#/portal/signup) [🪙 Pay with Crypto](https://darkwebinformer.com/crypto-payments) 

⚠ **Disclaimer**  
This report includes actual screenshots and/or text that **may include unredacted personally identifiable information (PII)** gathered from **publicly available sources**. The sensitive information presented within this report is intended **solely for cybersecurity awareness and threat intelligence purposes**. **Dark Web Informer explicitly condemns unauthorized access, distribution, or misuse** of the personal data displayed or referenced here. **Users must treat exposed data responsibly and ethically.**

---

## 📌 Overview

Threat actor **skart7** has posted a listing on a cybercrime forum offering a **pre-authentication Remote Code Execution (RCE)** exploit allegedly affecting **SonicWall SRA 4600** devices. This zero-day (nday) vulnerability is said to impact firmware versions **older than 9.0.0.10 or 10.2.0.7**. The actor claims the exploit is functional and requests a high price of **$60,000 USD**, accepting escrow-based transactions via the forum.

---

## 📊 Key Details

| Attribute          | Information                |
| ------------------ | -------------------------- |
| **Date**           | 2025-06-08, 7:17:11 PM     |
| **Threat Actor**   | skart7                     |
| **Victim Country** | Not specified              |
| **Industry**       | Not specified              |
| **Organization**   | Not specified              |
| **Victim Site**    | Not specified              |
| **Category**       | Vulnerability              |
| **Severity**       | Low (pending verification) |
| **Network**        | openweb                    |

Subscriber-only content…

---

## 🔗 Claim Post (Plain Text)

https://forum.exploit.in/topic/260540/  
*Tor Browser recommended for access*

---

## 📢 Threat Actor’s Claim

- **Exploit Type:** Pre-auth Remote Code Execution (RCE)
- **Target Device:** SonicWall SRA 4600
- **Affected Versions:** Firmware older than 9.0.0.10 or 10.2.0.7
- **Price:** $60,000 USD
- **Transaction Method:** Forum escrow accepted
- **Contact Methods:**
  - **Session ID:** 05121616a0966703a7f97bd2b8bce086e75139b239f6a8715d5fc1348adad1158
  - **TOX ID:** 2996C1DF03CB26B174523ADA4C7832BD6122BA8F1BA86CD17CD102376E7C1B254084E5DEFF4F
- **Note:** Serious buyers only, no time-wasters

---

## 📸 Screenshot

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/06/98235879235798239581.png)

---

## 🛡️ WhiteIntel.io Data Leak Information

(No victim site disclosed)

---

## ⚔️ Tactics, Techniques, and Procedures (TTPs)

| Tactic         | Technique ID | Description                                             |
| -------------- | ------------ | ------------------------------------------------------- |
| Initial Access | T1190        | Exploitation of public-facing application vulnerability |
| Execution      | T1203        | Exploitation of software vulnerability (Pre-auth RCE)   |

---

## 🚨 Potential Risks

- Unauthorized remote access to SonicWall VPN appliances
- Potential lateral movement within internal networks
- Exploitable entry point for ransomware or espionage operations
- Supply chain risk if deployed across multiple enterprise clients
- Unpatched appliances could be vulnerable in-the-wild

---

## ✅ Recommended Security Actions

- Immediately audit all SonicWall SRA 4600 devices for firmware version
- Upgrade to versions ≥ 9.0.0.10 or ≥ 10.2.0.7 as recommended
- Monitor for unusual activity or external access attempts
- Isolate vulnerable systems and enforce MFA on all remote access points
- Report any exploitation attempts to SonicWall and national CERT authorities

---

## 💡 Final Thoughts

The underground sale of a SonicWall SRA 4600 pre-auth RCE highlights the persistent risk posed by unpatched VPN devices in enterprise environments. While the credibility of this particular offering remains unverified, the potential for wide-scale exploitation should prompt immediate defensive measures by any organizations still running outdated firmware.

---

Stay informed at [**DarkWebInformer.com**](https://darkwebinformer.com/)