CVE-2025-40604: SonicWall Email Security Appliance 5000 Firmware
Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Affected products
- SonicWall Email Security Appliance 5000 Firmware: up to and including 10.0.33.8195
- SonicWall Email Security Appliance 5050 Firmware: up to and including 10.0.33.8195
- SonicWall Email Security Appliance 7000 Firmware: up to and including 10.0.33.8195
- SonicWall Email Security Appliance 7050 Firmware: up to and including 10.0.33.8195
- SonicWall Email Security Appliance 9000 Firmware: up to and including 10.0.33.8195
Published 2025-11-20. Last modified 2026-06-17.