Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: SonicWall initially investigated whether a reported wave of attacks against Gen 7 firewalls with SSLVPN enabled involved a new zero-day. In an August 2025 update, the company said it had high confidence the activity was not connected to a zero-day and found a significant correlation with the previously disclosed CVE-2024-40766. The counts reported at the time were bounded snapshots, not a current or comprehensive total.

Was the SonicWall SSL VPN activity a zero-day?

That was the initial concern, not SonicWall’s later conclusion. Early reporting and a CERT-EU advisory described the possibility of a zero-day while the activity was being investigated. SonicWall later said it had high confidence the incidents were not connected to a zero-day and correlated the activity with the known vulnerability CVE-2024-40766.

The chronology matters: the early alert reflected uncertainty during an active investigation; the later vendor assessment superseded that initial hypothesis. NHS England Digital also summarized SonicWall’s later position, but its alert is corroboration of the vendor’s public statement rather than independent forensic proof of every intrusion path.

What was reported, and how many attacks were involved?

Two figures circulated in August 2025, from different publishers and with different wording. They should not be added together or treated as the same measure.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SonicWall TZ470 Network Security/Firewall Appliance
  • The latest SonicWall TZ470 series, are the first desktop form factor nextgeneration firewalls (NGFW) with 1 or 5 Gigabit Ethernet interfaces. The series consist of a wide range of products to suit a variety of use cases.
  • Reduce complexity and get the business running without relying on IT personnel with easy onboarding using SonicExpress App and Zero-Touch Deployment, and easy management through a single pane of glass
  • Drive business growth by investing in next-gen appliances with multi-gigabit and advanced security features, to future-proof against the changing network and security landscape
  • Ensure seamless communication as stores talk to HQ via easy VPN connectivity which allows IT administrators to create a hub and spoke configuration for the safe transport of data between all locations
  • Hardware: Operating system: SonicOS 7. | Interfaces: 8x1GbE, 2x1GbE, 2 USB 3., 1 Console | Management: Network Security Manager, CLI, SSH, Web UI, GMS, REST APIs | VLAN interfaces: 128 | Access points supported (maximum): 32
Reported figure Attribution and meaning
Around 20 attacks beginning July 25, 2025 Huntress, as reported by The Hacker News on August 5, 2025. This is Huntress’s reported observation, not a comprehensive count of all affected organizations.
Fewer than 40 related incidents SonicWall said in its August 2025 update that it was investigating fewer than 40 incidents. This is the vendor’s investigation count, not a confirmed total of successful compromises.

Neither figure establishes an ongoing attack count or prevalence rate. The cited evidence describes the 2025 incident and investigation; it does not establish the activity’s status in October 2026.

What did SonicWall say linked the activity to CVE-2024-40766?

SonicWall reported a significant correlation between the investigated activity and CVE-2024-40766, which it had previously disclosed in advisory SNWLID-2024-0015. It also said many incidents involved migrations from Gen 6 to Gen 7 appliances where local user passwords were carried over and not reset.

Rank #2
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

Those are vendor findings about the incidents it reviewed; the available evidence does not establish one identical mechanism for every case. The migration and password detail is a reason to review local accounts and credentials, not proof that every affected system had been migrated or compromised in the same way.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should SonicWall administrators do?

The contemporaneous advisories focused on reducing exposure and strengthening existing appliance and account security. Apply measures appropriate to your environment, following current SonicWall guidance for the appliance and software version you operate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sonicwall NSA 2700 (02-SSC-4324)
  • The SonicWall Network Security appliance (NSa) Mid-Range Firewall is next-generation security designed specifically for businesses of 250 users and up.
  • Secure Remote Workers - SonicWall NetExtender provides an intuitive SSL-VPN connection client that’s easy to deploy and configure. Easily provide your remote workers with secure access to your corporate network from Linux, Mac and Windows devices.
  • Built-in Wireless Controller - Implement high-speed wireless security by combining a NSa Series next-generation firewall with a SonicWall SonicWave wireless access point. NSa Series firewalls and SonicWave access points both feature 2.5 GbE ports that enable multi-gigabit wireless throughput offered in Wave 2 wireless technology.
  • With cloud-based and on-box capabilities like TLS/SSL decryption and inspection, application intelligence and control, secure SD-WAN, real-time visualization, and WLAN management, SonicWall provides flexible, fast and cost-effective security to keep the threats out and your business thriving.
  • Highlights: 1 RU – Form Factor | 16 x 1 GbE interfaces | 3 x 10 GbE interfaces | 2 Gbps Threat and Malware Analysis Throughput | Enterprise Internet Edge Ready
  • Disable SSLVPN if it is not needed. If remote access is essential, avoid exposing it broadly and restrict connections to trusted source IP addresses where operationally feasible.
  • Enable available security services. Review the firewall’s security configuration and ensure applicable protective services are enabled.
  • Enforce multifactor authentication. Require MFA for remote-access accounts rather than relying on passwords alone.
  • Remove unused accounts. Review local and other user accounts, disable those no longer needed, and limit access to the minimum required.
  • Strengthen and reset credentials. Use strong, unique passwords. In particular, reset local passwords carried forward during a Gen 6-to-Gen 7 migration if they were not reset at the time.

CERT-EU’s initial guidance included these exposure and account controls while the zero-day possibility was still being assessed. SonicWall’s later finding makes the known-vulnerability correlation and carried-over-password issue especially relevant to account review, but it does not establish that these steps alone resolve every incident.

What is not established by the public reporting?

  • There is no supported basis here for treating the August 2025 counts as a current total or a measure of all compromised SonicWall devices.
  • The vendor’s correlation with CVE-2024-40766 does not prove that every incident had the same root cause or attack path.
  • The available reporting does not establish that the activity is continuing now.
  • No named individual was established as the source of a verified direct quotation; the findings are best described as SonicWall’s attributed statements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.