CVE-2025-40601: SonicWall SonicOS

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

Affected products

  • SonicWall SonicOS: from 7.1.1-7040, before 7.3.1-7013 (fixed in 7.3.1-7013); before 8.0.3-8011 (fixed in 8.0.3-8011)

Published 2025-11-20. Last modified 2026-06-17.