logo

New SonicWall SonicOS flaw allows hackers to crash firewalls

ID: a40533eb-ddba-5e64-9261-a514845c26b8

STIX ID: report--a40533eb-ddba-5e64-9261-a514845c26b8

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2025-11-20

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

SonicWall released advisories for multiple high-severity flaws — notably CVE-2025-40601 (stack-based buffer overflow in SonicOS SSLVPN affecting Gen7/Gen8 firewalls that can cause DoS) and two Email Security vulnerabilities (CVE-2025-40604 RCE and CVE-2025-40605 information disclosure) — providing fixed firmware versions and recommending immediate patching or temporary mitigations; no active exploitation has been reported, though the company cited past breaches and OVERSTEP rootkit incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.