CVE-2025-40601 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 20, 2025
Last Seen
November 23, 2025

CVE-2025-40601 is a vulnerability tracked across 2 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity November 23, 2025.

Related Threat Clusters

  • SonicWall SonicOS Vulnerability Allows Remote DoS Attacks

    SonicWall has issued a security advisory regarding a critical vulnerability in its SonicOS operating system, identified as CVE-2025-40601. This high-severity flaw affects Gen7 and Gen8 hardware and virtual appliances,…

    9 articles · Updated November 20, 2025
  • SonicWall SonicOS Flaw Allows Remote Firewall Crashes

    SonicWall has disclosed a critical vulnerability in its SonicOS SSLVPN service, tracked as CVE-2025-40601, which allows remote, unauthenticated attackers to crash Gen7 and Gen8 firewalls. The flaw, caused by a…

    11 articles · Updated November 24, 2025

Recent Intelligence Reports

  • SonicWall flags SSLVPN flaw allowing firewall crashes — Securityaffairs · November 23, 2025
  • SonicWall flags SSLVPN flaw allowing firewall crashes — Securityaffairs.Co · November 23, 2025
  • SonicWall Discloses Critical Buffer Overflow in SonicOS SSLVPN (CVE-2025-40601) — Webpronews · November 22, 2025
  • CVE-2025-40601: SonicOS SSLVPN Buffer Overflow Leads to Firewall Crash Risk, Patch Available — Socradar · November 21, 2025
  • Security vulnerabilities: Attackers can disable SonicWall SonicOS SSLVPN — Heise.De · November 21, 2025
  • Critical SonicOS Flaw Enables Hackers To Crash SonicWall Firewall Systems — Linkedin · November 20, 2025
  • New SonicWall SonicOS flaw allows hackers to crash firewalls — Bleepingcomputer · November 20, 2025

CVSS v3.1 Breakdown