SonicWall: Attackers did not exploit zero-day vulnerability to compromise Gen 7 firewalls
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40766 | Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls) CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile). Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents. | 9.8 | 18% | KEV ransomware |
| mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances) |
Full article369 words · extracted from helpnetsecurity.com · click to collapse
Akira ransomware affiliates are not leveraging an unknown, zero-day vulnerability in SonicWall Gen 7 firewalls to breach corporate networks, the security vendor shared today.
“Instead, there is a significant correlation with threat activity related to CVE-2024-40766, which was previously disclosed and documented in our public advisory.”
What happened?
Since July 15, 2025, researchers have observed a notable surge in ransomware activity targeting SonicWall firewalls, specifically via their SSL VPN functionality, and posited that the attackers might be leveraging a zero-day vulnerability because, in some cases, fully patched SonicWall devices were affected following credential rotation and despite time-based one-time password (TOTP) multi-factor authentication (MFA) being enabled.
This wave of attacks aligns with patterns previously seen from the Akira ransomware-as-a-service group.
A SonicWall spokesperson told Help Net Security that there have been fewer than 40 confirmed cases, and the attacks seem to be linked to legacy credential use during migrations from Gen 6 to Gen 7 firewalls.
Apparently, local user passwords were carried over during the migration and not reset as the company advised in the original advisory. (CVE-2024-40766 also affects Gen 7 firewalls running SonicOS 7.0.1-5035 and older versions.)
Mitigation and remediation
Since the security updates for CVE-2024-40766, newer versions of SonicOS have been released, and SonicWall pointed out that SonicOS 7.3 has additional protection against brute-force password and MFA attacks, such as admin/user lockout (enabled by default but has to be configured) and password complexity enforcement (has to be enabled by admins).
Thus, they are urging organizations using Gen 7 firewalls to upgrade to it. Organizations that have imported configurations from Gen 6 to newer firewalls should also:
- Update the firmware to version 7.3.0
- Reset all local user account passwords for any accounts with SSLVPN access
- Consider enabling available protections (Botnet Protection, Geo-IP Filtering, etc.)
- Remove unused user accounts
- Enforce MFA and strong password policies.
Huntress researchers said that they’ve detected around 28 attacks that have many similarities but also some differences.
Huntress and GuidePoint Security have shared indicators of compromise associated with the campaign and listed the various actions and tools used by the attackers.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/07/sonicwall-gen-7-firewalls-exploit-vulnerability/