SonicWall is asking customers to fix SonicOS bugs that allow hackers to crash firewalls


  • SonicWall Patches SSLVPN Vulnerability CVE-2025-40601 Enables Unauthorized DoS Attacks on Gen7/Gen8 Firewalls
  • No exploit seen yet; users are encouraged to disable SSLVPN or restrict access if updates are delayed
  • Also fixed are two flaws in the Email Security Appliance (CVE-2025-40604/40605) that prevent code execution and data access

SonicWall has released a patch for a serious vulnerability in its SonicOS SSLVPN service and urged all users to update their firewalls immediately.

In a security advisory, the company said it discovered a stack-based buffer overflow vulnerability in the SonicOS SSLVPN service that allows a remote, unauthorized attacker to cause a Denial of Service (DoS) and essentially crash the firewall.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top