SonicOS SSLVPN flaw enables remote firewall crash
A stack-based buffer overflow in SonicOS SSLVPN service allows unauthenticated attackers to crash affected firewalls running versions 7.3.0-7012 or 8.0.2-8011.
SonicWall has disclosed CVE-2025-40601, a stack-based buffer overflow vulnerability in the SSLVPN service of SonicOS that could allow remote unauthenticated attackers to trigger a denial-of-service condition, causing affected firewalls to crash. The vulnerability only impacts devices with the SSLVPN interface or service enabled. Affected versions include SonicOS 7.3.0-7012 and older (excluding the 7.0.1 branch) and SonicOS 8.0.2-8011 and older.
SonicWall PSIRT reports no evidence of active exploitation in the wild, and no proof-of-concept code has been publicly released. The vendor has issued patches for affected versions. Organizations running SonicWall firewalls with SSLVPN enabled should prioritize applying the available updates.
The vulnerability represents a moderate risk to organizations relying on SonicWall appliances for perimeter security, particularly those exposing SSLVPN services to the internet. While exploitation would result in service disruption rather than data compromise, the unauthenticated remote attack vector and potential for firewall crashes warrant prompt remediation.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-sonicos-could-allow-for-denial-of-service-dos_2025-110
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free