SonicWall SonicOS SSLVPN stack-based buffer overflow DoS denial-of-service flaw (CVE-2025-40601)
Vulnerability
Summary
Hide ▲
Show ▼
SonicWall has patched CVE-2025-40601, a stack-based buffer overflow in the SonicOS SSLVPN service that can let a remote unauthenticated attacker crash Gen7 and Gen8 firewalls. The vendor says it is not aware of active exploitation and has not seen a public proof-of-concept. Administrators who cannot patch immediately are advised to disable SSLVPN or restrict access to trusted sources.
Related Happenings
Check Point VPN CVE-2026-50751 targeted exploitation wave
Exploitation Wave
H score47
First: 08.06.2026 17:17
Last: 08.06.2026 17:17
Sources 1
About this happening:
CVE-2026-50751 is an active exploitation wave against Check Point Remote Access VPN and Mobile Access deployments that use deprecated IKEv1. The flaw is an a...
Check Point VPN CVE-2026-50751 targeted exploitation wave
Exploitation WaveAbout this happening: CVE-2026-50751 is an active exploitation wave against Check Point Remote Access VPN and Mobile Access deployments that use deprecated IKEv1. The flaw is an a...
ChromaDB Python API exposure mitigation (CVE-2026-45829)
Advisory/Mitigation
H score25
First: 20.05.2026 01:25
Last: 20.05.2026 01:25
Sources 1
About this happening:
HiddenLayer urged ChromaDB users to harden exposed deployments because CVE-2026-45829 can still enable code execution on the Python FastAPI server. Until patch sta...
ChromaDB Python API exposure mitigation (CVE-2026-45829)
Advisory/MitigationAbout this happening: HiddenLayer urged ChromaDB users to harden exposed deployments because CVE-2026-45829 can still enable code execution on the Python FastAPI server. Until patch sta...
Akira SonicWall SSL VPN MFA-bypass campaign
Campaign
H score24
First: 28.09.2025 21:49
Last: 28.09.2025 21:49
Sources 1
About this happening:
In late September, Arctic Wolf reported an ongoing Akira campaign against SonicWall firewalls and SSL VPN accounts that could log in even when OTP MFA was enab...
Akira SonicWall SSL VPN MFA-bypass campaign
CampaignAbout this happening: In late September, Arctic Wolf reported an ongoing Akira campaign against SonicWall firewalls and SSL VPN accounts that could log in even when OTP MFA was enab...
Latest development: 11.10.2025 16:30
Huntress warned that Akira-affiliated threat actors rapidly authenticated into multiple accounts across compromised SonicWall SSL VPN devices, affecting more than 100 accounts across 16 customer environments and beginning on October 4, 2025. In some cases the actors disconnected after a short time, while in others they performed network scanning and attempted to access local Windows accounts; authentications on the SonicWall devices originated from 202.155.8[.]73 and appeared to rely on valid credentials rather than brute force.
SonicWall SSL VPN CVE-2024-40766 active exploitation wave
Exploitation Wave
H score9
First: 11.09.2025 19:32
Last: 11.09.2025 19:32
Sources 1
About this happening:
Akira is driving a renewed wave of active exploitation of CVE-2024-40766 against SonicWall SSL VPNs, creating immediate unauthorized-access risk for exposed device...
SonicWall SSL VPN CVE-2024-40766 active exploitation wave
Exploitation WaveAbout this happening: Akira is driving a renewed wave of active exploitation of CVE-2024-40766 against SonicWall SSL VPNs, creating immediate unauthorized-access risk for exposed device...
Akira ransomware group SonicWall initial-access campaign
Campaign
H score60
First: 11.09.2025 13:33
Last: 11.09.2025 13:33
Sources 1
About this happening:
The Akira ransomware group is associated with a continuing SonicWall SSL VPN initial-access campaign that uses CVE-2024-40766 and related credential abuse to breach vi...
Akira ransomware group SonicWall initial-access campaign
CampaignAbout this happening: The Akira ransomware group is associated with a continuing SonicWall SSL VPN initial-access campaign that uses CVE-2024-40766 and related credential abuse to breach vi...
Latest development: 04.12.2025 00:06
Marquis Software Solutions says a ransomware attack on August 14, 2025 breached its network through a SonicWall firewall and exposed files containing personal information for customers of 74 banks and credit unions, affecting over 400,000 customers; Marquis says there is no evidence the data has been misused or published anywhere.
Timeline
-
20.11.2025 17:56 2 articles · 7mo ago
SonicWall discloses CVE-2025-40601 in SonicOS SSLVPN
Initial DisclosureSonicWall urged customers to patch CVE-2025-40601, a stack-based buffer overflow in the SonicOS SSLVPN service that can let a remote unauthenticated attacker cause Denial of Service (DoS) and crash impacted Gen7 hardware Firewalls, Gen7 virtual Firewalls (NSv), and Gen8 Firewalls. SonicWall PSIRT said it is not aware of active exploitation in the wild, no public PoC has been made public, and administrators who cannot immediately deploy the updates are advised to disable the SonicOS SSLVPN service or restrict access to trusted sources.
Show sources
- New SonicWall SonicOS flaw allows hackers to crash firewalls — www.bleepingcomputer.com — 20.11.2025 17:56
- New SonicWall SonicOS flaw allows hackers to crash firewalls — www.bleepingcomputer.com — 20.11.2025 17:56