# SonicOS SSLVPN flaw enables remote firewall crash

Published: 2026-06-09 · Severity: medium
Canonical: https://vorant.io/reports/ad8d8710-8971-49ce-a29a-ff68831fe23f/sonicos-sslvpn-flaw-enables-remote-firewall-crash

> A stack-based buffer overflow in SonicOS SSLVPN service allows unauthenticated attackers to crash affected firewalls running versions 7.3.0-7012 or 8.0.2-8011.

SonicWall has disclosed CVE-2025-40601, a stack-based buffer overflow vulnerability in the SSLVPN service of SonicOS that could allow remote unauthenticated attackers to trigger a denial-of-service condition, causing affected firewalls to crash. The vulnerability only impacts devices with the SSLVPN interface or service enabled. Affected versions include SonicOS 7.3.0-7012 and older (excluding the 7.0.1 branch) and SonicOS 8.0.2-8011 and older.

SonicWall PSIRT reports no evidence of active exploitation in the wild, and no proof-of-concept code has been publicly released. The vendor has issued patches for affected versions. Organizations running SonicWall firewalls with SSLVPN enabled should prioritize applying the available updates.

The vulnerability represents a moderate risk to organizations relying on SonicWall appliances for perimeter security, particularly those exposing SSLVPN services to the internet. While exploitation would result in service disruption rather than data compromise, the unauthenticated remote attack vector and potential for firewall crashes warrant prompt remediation.

## Mentioned in this report

- Vulnerabilities: CVE-2025-40601

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-sonicos-could-allow-for-denial-of-service-dos_2025-110

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ad8d8710-8971-49ce-a29a-ff68831fe23f/sonicos-sslvpn-flaw-enables-remote-firewall-crash.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
