logo

SonicWall firewall bug leveraged in attacks after PoC exploit release

ID: 1b61fb83-93ac-503f-a148-825202fa1c49

STIX ID: report--1b61fb83-93ac-503f-a148-825202fa1c49

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-02-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SonicWall disclosed a critical SSLVPN authentication-bypass flaw (CVE-2024-53704) affecting SonicOS 7.1.x and 8.0.0 that allows remote attackers to hijack active VPN sessions; firmware updates and mitigations were released on January 7, but a public proof-of-concept published in February prompted observed exploitation attempts and left thousands of unpatched devices exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.