logo

SonicWall firewall exploit lets hackers hijack VPN sessions, patch now

ID: 72a289cd-4636-5b5c-a4c7-522c82872376

STIX ID: report--72a289cd-4636-5b5c-a4c7-522c82872376

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-02-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** A critical SonicWall SSL VPN authentication bypass (CVE-2024-53704) was analyzed and a proof-of-concept exploit released by Bishop Fox; the flaw allows unauthenticated remote attackers to hijack active SSL VPN sessions, access user bookmarks and VPN configuration, and open tunnels into internal networks, with patches available but many devices still exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.