Bleepingcomputer
SonicWall SonicOS Flaw Allows Remote Firewall Crashes
First seen 27 Nov 2025, 20:34 UTC
•



+6
•23.4
Export
Article Content
Browse articles
SonicWall has disclosed a critical vulnerability in its SonicOS SSLVPN service, tracked as CVE-2025-40601, which allows remote, unauthenticated attackers to crash Gen7 and Gen8 firewalls. The flaw, caused by a stack-based buffer overflow, poses significant risks for organizations using SonicWall for network security. SonicWall has urged customers to apply patches immediately, although there are currently no reports of active exploitation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
Exploitation of Remote Services in Cyber Attacks
CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls
Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766