Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Sony announces PlayStation Plus Extra triple-A free games for mid-December 2025 following last-minute leak

    Nintendo Switch 2 could become more expensive as RAM costs jump 41%

    The James Webb Space Telescope sets a record with the discovery of a 13 billion-year-old supernova

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025

      From Steve Bannon to Elizabeth Warren, backlash erupts over push to block states from regulating AI

      November 23, 2025

      Insurance companies are trying to avoid big payouts by making AI safer

      November 19, 2025
    • Business

      Public GitLab repositories exposed more than 17,000 secrets

      November 29, 2025

      ASUS warns of new critical auth bypass flaw in AiCloud routers

      November 28, 2025

      Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools

      November 18, 2025

      Government faces questions about why US AWS outage disrupted UK tax office and banking firms

      October 23, 2025

      Amazon’s AWS outage knocked services like Alexa, Snapchat, Fortnite, Venmo and more offline

      October 21, 2025
    • Crypto

      MicroStrategy Calls Morgan Stanley’s Index Plan “Discriminatory” as Consultation Continues

      December 10, 2025

      Fed Cuts Rates 25bps, But the Real Shock Is What Comes Next

      December 10, 2025

      Millions of Xiaomi Users to Gain Instant Crypto Access with Sei From 2026

      December 10, 2025

      3 Altcoins That Can Hit All-Time Highs Before Christmas

      December 10, 2025

      350 Million XRP Changes Hands as Bigger Whales Take Over Amid Price Downtrend

      December 10, 2025
    • Technology

      Sony announces PlayStation Plus Extra triple-A free games for mid-December 2025 following last-minute leak

      December 11, 2025

      Nintendo Switch 2 could become more expensive as RAM costs jump 41%

      December 11, 2025

      The James Webb Space Telescope sets a record with the discovery of a 13 billion-year-old supernova

      December 11, 2025

      Call of Duty: Black Ops 7 player count reportedly higher than Battlefield 6 or Arc Raiders

      December 11, 2025

      Upcoming 12th-gen iPad to arrive with two significant upgrades

      December 11, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»New SonicWall SonicOS flaw allows hackers to crash firewalls
    Technology

    New SonicWall SonicOS flaw allows hackers to crash firewalls

    TechAiVerseBy TechAiVerseNovember 21, 2025No Comments3 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    New SonicWall SonicOS flaw allows hackers to crash firewalls
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    New SonicWall SonicOS flaw allows hackers to crash firewalls

    American cybersecurity company SonicWall urged customers today to patch a high-severity SonicOS SSLVPN security flaw that can allow attackers to crash vulnerable firewalls.

    Tracked as CVE-2025-40601, this denial-of-service vulnerability is caused by a stack-based buffer overflow impacting Gen8 and Gen7 (hardware and virtual) firewalls.

    “A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash,” SonicWall said.

    “SonicWall PSIRT is not aware of active exploitation in the wild. No reports of a PoC have been made public and malicious use of this vulnerability has not been reported to SonicWall.”

    However, the company added that its Gen6 firewalls, as well as the SMA 1000 and SMA 100 series SSL VPN products, are not vulnerable to attacks potentially targeting this vulnerability.

    While SonicWall has yet to find any evidence that attackers are exploiting CVE-2025-40601 in the wild, the company “strongly” urged network defenders to apply the guidance shared in today’s security advisory.

    Affected Platforms Fixed versions
    Gen7 hardware Firewalls – TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570, TZ570W, TZ570P, TZ670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700
    Gen7 virtual Firewalls (NSv) – NSV270, NSv470, NSv870 (ESX, KVM, HYPER-V, AWS, Azure)
    7.3.1-7013 and higher versions
    Gen8 Firewalls – TZ80, TZ280, TZ380, TZ480, TZ580, TZ680, NSa 2800, NSa 3800, NSa 4800, NSa 5800 8.0.3-8011 and higher versions

    Admins who can’t immediately deploy today’s security updates are advised to disable the SonicOS SSLVPN service or to modify rules to limit access to the SonicWall firewall appliance to trusted sources.

    Today, the cybersecurity firm also patched two vulnerabilities impacting its Email Security appliances (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare, and Hyper-V), enabling remote attackers to gain persistent arbitrary code execution (CVE-2025-40604) and access restricted information (CVE-2025-40605).

    “SonicWall strongly advises users of the Email Security products (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V) to upgrade,” it noted in a separate advisory.

    Earlier this month, SonicWall confirmed that a state-sponsored hacking group was behind a September security breach that exposed customers’ firewall configuration backup files, roughly one month after researchers warned that threat actors had compromised over 100 SonicWall SSLVPN accounts using stolen credentials.

    In September, it also released a firmware update to help IT admins remove OVERSTEP rootkit malware deployed in attacks targeting SMA 100 series devices.

    7 Security Best Practices for MCP

    As MCP (Model Context Protocol) becomes the standard for connecting LLMs to tools and data, security teams are moving fast to keep these new services safe.

    This free cheat sheet outlines 7 best practices you can start using today.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleGrok says Elon Musk is better than basically everyone, except Shohei Ohtani
    Next Article Salesforce investigates customer data theft via Gainsight breach
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Sony announces PlayStation Plus Extra triple-A free games for mid-December 2025 following last-minute leak

    December 11, 2025

    Nintendo Switch 2 could become more expensive as RAM costs jump 41%

    December 11, 2025

    The James Webb Space Telescope sets a record with the discovery of a 13 billion-year-old supernova

    December 11, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025507 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025174 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202586 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202566 Views
    Don't Miss
    Technology December 11, 2025

    Sony announces PlayStation Plus Extra triple-A free games for mid-December 2025 following last-minute leak

    Sony announces PlayStation Plus Extra triple-A free games for mid-December 2025 following last-minute leak -…

    Nintendo Switch 2 could become more expensive as RAM costs jump 41%

    The James Webb Space Telescope sets a record with the discovery of a 13 billion-year-old supernova

    Call of Duty: Black Ops 7 player count reportedly higher than Battlefield 6 or Arc Raiders

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Sony announces PlayStation Plus Extra triple-A free games for mid-December 2025 following last-minute leak

    December 11, 20252 Views

    Nintendo Switch 2 could become more expensive as RAM costs jump 41%

    December 11, 20252 Views

    The James Webb Space Telescope sets a record with the discovery of a 13 billion-year-old supernova

    December 11, 20252 Views
    Most Popular

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    Volkswagen’s cheapest EV ever is the first to use Rivian software

    March 12, 20250 Views

    Startup studio Hexa acquires majority stake in Veevart, a vertical SaaS platform for museums

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.