CVE-2025-40601: SonicWall SonicOS
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
Affected products
- SonicWall SonicOS: from 7.1.1-7040, before 7.3.1-7013 (fixed in 7.3.1-7013); before 8.0.3-8011 (fixed in 8.0.3-8011)
Published 2025-11-20. Last modified 2026-06-17.