CVE-2025-40600: Critical severity SonicWall SonicOS vulnerability
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40600?
CVE-2025-40600 is considered a high-severity vulnerability due to its potential to allow remote unauthenticated attackers to disrupt services.
How do I fix CVE-2025-40600?
To fix CVE-2025-40600, ensure that your SonicWall SonicOS is updated to the latest patched version as recommended by the vendor.
Who is affected by CVE-2025-40600?
CVE-2025-40600 affects all versions of SonicWall SonicOS that use the SSL VPN interface.
What type of attack does CVE-2025-40600 enable?
CVE-2025-40600 enables a remote unauthenticated attacker to exploit an externally-controlled format string vulnerability, leading to service disruption.
Can CVE-2025-40600 be exploited without authentication?
Yes, CVE-2025-40600 can be exploited by remote attackers without any authentication.