SonicWall Asks Customers to Patch SonicOS Flaw That Allows Hackers to Block Firewalls



  • SonicWall Patches SSLVPN CVE-2025-40601 Flaw, Allowing Unauthenticated DoS Attacks on Gen7/Gen8 Firewalls
  • Exploitation has not yet been seen; Users are urged to disable SSLVPN or restrict access if updates are delayed.
  • Also fixed two flaws in the Email Security device (CVE-2025-40604/40605), which prevented code execution and data access.

SonicWall released a patch for a high severity vulnerability in its SonicOS SSLVPN service and urged all users to update their firewalls immediately.

In a security advisory, the company said it discovered a stack-based buffer overflow vulnerability in SonicOS’s SSLVPN service, which allows an unauthenticated, remote attacker to cause Denial of Service (DoS) and essentially crash the firewall.



Leave a Comment

Your email address will not be published. Required fields are marked *