Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-40601


A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.


Published

2025-11-20T15:17:28.570

Last Modified

2025-12-12T15:57:37.410

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-121

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sonicwall sonicos < 7.3.1-7013 Yes
Hardware sonicwall nsa_2700 - No
Hardware sonicwall nsa_3700 - No
Hardware sonicwall nsa_4700 - No
Hardware sonicwall nsa_5700 - No
Hardware sonicwall nsa_6700 - No
Hardware sonicwall nssp_10700 - No
Hardware sonicwall nssp_11700 - No
Hardware sonicwall nssp_13700 - No
Hardware sonicwall nssp_15700 - No
Hardware sonicwall nsv270 - No
Hardware sonicwall nsv470 - No
Hardware sonicwall nsv870 - No
Hardware sonicwall tz270 - No
Hardware sonicwall tz270w - No
Hardware sonicwall tz370 - No
Hardware sonicwall tz370w - No
Hardware sonicwall tz470 - No
Hardware sonicwall tz470w - No
Hardware sonicwall tz570 - No
Hardware sonicwall tz570p - No
Hardware sonicwall tz570w - No
Hardware sonicwall tz670 - No
Operating System sonicwall sonicos < 8.0.3-8011 Yes
Hardware sonicwall nsa_2800 - No
Hardware sonicwall nsa_3800 - No
Hardware sonicwall nsa_4800 - No
Hardware sonicwall nsa_5800 - No
Hardware sonicwall tz280 - No
Hardware sonicwall tz380 - No
Hardware sonicwall tz480 - No
Hardware sonicwall tz580 - No
Hardware sonicwall tz680 - No
Hardware sonicwall tz80 - No

References