Today, SonicWall, an American cybersecurity business, asked its clients to fix a high-severity SonicOS SSLVPN security vulnerability that might let attackers take down susceptible firewalls.
This denial-of-service vulnerability, known as CVE-2025-40601, affects Gen8 and Gen7 (hardware and virtual) firewalls and is brought on by a stack-based buffer overflow.
According to SonicWall, a stack-based buffer overflow vulnerability in the SonicOS SSLVPN service enables a remote unauthenticated attacker to inflict Denial of Service (DoS), which may result in the crash of an affected firewall.
There are no known instances of active exploitation in the wild, according to SonicWall PSIRT. There have been no public reports of a proof of concept, and SonicWall has not received any reports of malicious usage of this issue.
The SMA 1000 and SMA 100 series SSL VPN devices, along with its Gen6 firewalls, are not susceptible to assaults read more about New SonicWall SonicOS flaw allows hackers to crash firewalls.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
