SonicWall has disclosed a critical buffer overflow vulnerability, tracked as CVE-2025-40601, in the SSLVPN service of its SonicOS operating system. This flaw allows remote, unauthenticated attackers to trigger a firewall crash, resulting in a Denial-of-Service (DoS) condition. The vulnerability affects both hardware and virtual firewalls in the Gen7 and Gen8 product lines, including models such as TZ270–TZ670, NSa 2700–6700, NSsp 10700–15700, and their virtual equivalents on platforms like ESX, KVM, Hyper-V, AWS, and Azure. The issue is present in software versions Gen7 7.3.0-7012 and older, and Gen8 8.0.2-8011 and older, but does not impact Gen6 or SMA series devices.
SonicWall has released patches to address the vulnerability and recommends immediate updates for affected systems. There is currently no evidence of active exploitation or remote code execution capabilities associated with this flaw; the primary risk is service disruption due to firewall crashes. Administrators are urged to verify whether the SSLVPN interface is enabled and to apply the necessary security updates to mitigate potential DoS attacks targeting this vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
At disclosure, reports indicated that a vendor fix was available for affected SonicWall firewall products. The update was presented as the recommended mitigation for the SSLVPN buffer overflow issue.
SonicWall warned of a new pre-authentication buffer overflow vulnerability, CVE-2025-40601, affecting SonicOS SSLVPN. The flaw could allow a remote attacker to trigger firewall crashes, causing denial-of-service conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethecyberthrone.in
Open sourcesecurityonline.info
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.