SonicWall warned that multiple critical flaws in Gen 6, Gen 6.5, Gen 7, and TZ80 firewalls could allow authentication bypass, arbitrary outbound connections, privileged access, and possible remote code execution on exposed devices. The disclosed issues include CVE-2024-40762, CVE-2024-53704, CVE-2024-53705, and CVE-2024-53706, with guidance to immediately install vendor updates and, if patching is delayed, disable Internet-exposed SSLVPN or restrict access to trusted sources. Authorities also urged organizations to review logs for suspicious local-user login attempts and other anomalous access patterns.
Subsequent incident reporting tied real-world compromises of SonicWall Gen 7 firewalls with SSLVPN enabled to CVE-2024-40766 and password-related weaknesses introduced during Gen 6 to Gen 7 migrations, rather than to a new zero-day as initially feared. SonicWall said many successful intrusions appeared to involve migrated local user passwords that had not been reset, creating an opening for network breaches and potential ransomware activity. Recommended mitigations include upgrading to firmware 7.3.0, resetting local SSLVPN user passwords, disabling unused accounts, enabling MFA, Botnet Protection, and Geo-IP Filtering, and limiting SSLVPN access by IP where the service remains necessary.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2025-08-07, SonicWall updated its guidance and said the investigated activity was not caused by a zero-day. Instead, it tied successful compromises to CVE-2024-40766 and password-related weaknesses affecting local users migrated from Gen 6 to Gen 7 when passwords had not been reset.
On 2025-08-06, Finland's National Cyber Security Centre published an alert that SonicWall Gen 7 SSLVPN weaknesses were being exploited in breaches and urged organizations to inspect exposed devices for signs of compromise. It said it was not aware of successful exploitation in Finland at that time and recommended mitigations such as firmware upgrades, password resets, MFA, and disabling unnecessary SSLVPN access.
On 2025-08-04, SonicWall warned that a possible zero-day affecting Gen 7 firewalls with SSLVPN enabled may have been used in multiple intrusions. The activity was described as potentially enabling arbitrary code execution, network compromise, and ransomware attacks.
On 2025-01-07, SonicWall disclosed five vulnerabilities affecting Gen 6, Gen 6.5, Gen 7, and TZ80 firewall products, including authentication bypass, SSRF, weak randomness, and cloud NSv issues. The company issued software updates and advised customers to patch immediately or restrict Internet-exposed SSLVPN access.
On 2024-08-22, SonicWall released fixes for CVE-2024-40766, a remote code execution vulnerability affecting Gen 5 and Gen 6 firewalls and Gen 7 devices running SonicOS 7.0.1-5035 or earlier. The flaw exposed management interfaces and, as later clarified, local SSLVPN accounts on affected unpatched devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.