SonicWall asks customers to fix SonicOS flaw that allows hackers to crash firewalls


  • SonicWall Patches SSLVPN CVE-2025-40601, Allowing Unauthenticated DoS Attacks on Gen7/Gen8 Firewalls
  • No exploitation observed for the moment; users are advised to disable SSLVPN or restrict access if updates are delayed
  • Two vulnerabilities in the Email Security appliance (CVE-2025-40604/40605) were also fixed, preventing code execution and data access.

SonicWall has released a patch for a high severity vulnerability in its SonicOS SSLVPN service and urged all users to update their firewall immediately.

In a security advisory, the company said it discovered a stack-based buffer overflow vulnerability in the SonicOS SSLVPN service, which allows an unauthenticated, remote attacker to cause a denial of service (DoS) and essentially crash the firewall.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top