CVE-2025-40600

CRITICAL
Published Jul 29, 2025 Modified Aug 11, 2025 CWE-134

Description

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-134 CWE-134

Affected Products

Vendor Product
sonicwall sonicos
sonicwall nsa_2700
sonicwall nsa_3700
sonicwall nsa_4700
sonicwall nsa_5700
sonicwall nsa_6700
sonicwall nssp_10700
sonicwall nssp_11700
sonicwall nssp_13700
sonicwall nssp_15700
sonicwall nsv270
sonicwall nsv470
sonicwall nsv870
sonicwall tz270
sonicwall tz270w
sonicwall tz370
sonicwall tz370w
sonicwall tz470
sonicwall tz470w
sonicwall tz570
sonicwall tz570p
sonicwall tz570w
sonicwall tz670

References

Frequently Asked Questions

What is CVE-2025-40600? +
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. It has a CVSS v3.1 base score of 9.8 (CRITICAL).
How severe is CVE-2025-40600? +
CVE-2025-40600 has a CVSS v3.1 score of 9.8 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2025-40600? +
CVE-2025-40600 affects products from sonicwall, specifically: nsa_2700, nsa_3700, nsa_4700, nsa_5700, nsa_6700, nssp_10700, nssp_11700, nssp_13700, nssp_15700, nsv270, nsv470, nsv870, sonicos, tz270, tz270w, tz370, tz370w, tz470, tz470w, tz570, tz570p, tz570w, tz670. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-40600? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-40600 — free, no signup required.

Start Free Scan