Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteSonicWall says it has high confidence that the SSLVPN activity it investigated in 2025 was not connected to a zero-day, but was significantly correlated with the previously disclosed CVE-2024-40766. The vendor said it was investigating fewer than 40 incidents and that many involved local user passwords carried over during Gen 6-to-Gen 7 firewall migrations without being reset. For administrators, the immediate priorities are to follow current model-specific firmware guidance, reset relevant local SSLVPN passwords, and review access protections and activity.
Was the SonicWall SSLVPN attack a zero-day?
SonicWall’s August 22, 2025 update said the company had “high confidence” that the recent SSLVPN activity was not connected to a zero-day vulnerability. It said the activity instead had a “significant correlation” with threat activity related to CVE-2024-40766, which SonicWall had previously disclosed in a public advisory. This is SonicWall’s assessment; the notice does not establish that every incident was conclusively attributed to the vulnerability.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
SonicWall TZ470 Network Security/Firewall Appliance | $825.30 | Buy on Amazon |
| 2 |
|
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed,... | $468.00 | Buy on Amazon |
| 3 |
|
Sonicwall NSA 2700 (02-SSC-4324) | $2,159.20 | Buy on Amazon |
The timing explains the shift in the story. SonicWall published its notice on August 4 about cyber activity involving Gen 7 and newer firewalls with SSLVPN enabled. A TechRadar Pro report on August 6 described a then-unresolved zero-day possibility. It reported that Arctic Wolf Labs had observed an uptick in malicious logins from mid-July and initially speculated that a zero-day could explain access to some fully patched endpoints. The report also noted that attackers might have used stolen active credentials and that Akira ransomware infections followed some malicious logins. Those were contemporaneous observations and hypotheses, not SonicWall’s later attribution. TechRadar Pro’s August 6 report covers that earlier stage.
In its August 22 update, SonicWall said it was investigating fewer than 40 incidents related to the activity. That is the vendor’s incident count at that time, not an independently verified total or a measure of how widespread exploitation was.
#1 Best Overall
- The latest SonicWall TZ470 series, are the first desktop form factor nextgeneration firewalls (NGFW) with 1 or 5 Gigabit Ethernet interfaces. The series consist of a wide range of products to suit a variety of use cases.
- Reduce complexity and get the business running without relying on IT personnel with easy onboarding using SonicExpress App and Zero-Touch Deployment, and easy management through a single pane of glass
- Drive business growth by investing in next-gen appliances with multi-gigabit and advanced security features, to future-proof against the changing network and security landscape
- Ensure seamless communication as stores talk to HQ via easy VPN connectivity which allows IT administrators to create a hub and spoke configuration for the safe transport of data between all locations
- Hardware: Operating system: SonicOS 7. | Interfaces: 8x1GbE, 2x1GbE, 2 USB 3., 1 Console | Management: Network Security Manager, CLI, SSH, Web UI, GMS, REST APIs | VLAN interfaces: 128 | Access points supported (maximum): 32
What is CVE-2024-40766?
NIST describes CVE-2024-40766 as an improper access control vulnerability in SonicOS management access. Under specific conditions, it could allow unauthorized access to resources and cause a firewall crash. NIST lists Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 or earlier, as affected. NIST assigns it a CVSS 3.1 base score of 9.8, Critical. NIST’s CVE-2024-40766 record provides the vulnerability details.
The “year-old” framing refers to the 2024 disclosure that SonicWall later correlated with activity investigated in 2025. The disclosure, reports of exploitation, the 2025 investigation, and the vendor’s August attribution update are distinct events; they should not be treated as proof that every 2025 login or incident resulted from this vulnerability.
Rank #2
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
Why did Gen 6-to-Gen 7 migrations matter?
SonicWall said many of the incidents under investigation involved migrations from Gen 6 to Gen 7 in which local user passwords were carried forward and not reset. That observation does not mean every incident involved a migration or that every migrated account was compromised. It does make migrated local SSLVPN credentials an important priority for administrators.
SonicWall’s notice applies to Gen 7 and newer firewalls with SSLVPN enabled. The vulnerability record’s affected-product list is different: it identifies Gen 5 and Gen 6, plus certain Gen 7 firmware. Because the applicability depends on model and firmware, verify the current SonicWall advisory and lifecycle guidance for the specific appliance before choosing a firmware update. The available notice recommends SonicOS 7.3.0 in the migration scenario for enhanced protections against brute-force password and MFA attacks, but it is not a universal, model-by-model patch instruction.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
- The SonicWall Network Security appliance (NSa) Mid-Range Firewall is next-generation security designed specifically for businesses of 250 users and up.
- Secure Remote Workers - SonicWall NetExtender provides an intuitive SSL-VPN connection client that’s easy to deploy and configure. Easily provide your remote workers with secure access to your corporate network from Linux, Mac and Windows devices.
- Built-in Wireless Controller - Implement high-speed wireless security by combining a NSa Series next-generation firewall with a SonicWall SonicWave wireless access point. NSa Series firewalls and SonicWave access points both feature 2.5 GbE ports that enable multi-gigabit wireless throughput offered in Wave 2 wireless technology.
- With cloud-based and on-box capabilities like TLS/SSL decryption and inspection, application intelligence and control, secure SD-WAN, real-time visualization, and WLAN management, SonicWall provides flexible, fast and cost-effective security to keep the threats out and your business thriving.
- Highlights: 1 RU – Form Factor | 16 x 1 GbE interfaces | 3 x 10 GbE interfaces | 2 Gbps Threat and Malware Analysis Throughput | Enterprise Internet Edge Ready
What should you do if you migrated a SonicWall configuration?
- Verify firmware guidance for the appliance. Check the current SonicWall security advisory and lifecycle information for your exact model and installed firmware. Apply the firmware SonicWall identifies as appropriate for that device; do not assume that a version recommended for one model applies to all others.
- Reset local passwords for accounts with SSLVPN access. Prioritize passwords carried over during a Gen 6-to-Gen 7 migration. SonicWall’s recommendation is for relevant local accounts, not every user record stored or referenced by the firewall.
- Confirm which users are local. SonicWall says its reset recommendation does not apply to auto-generated or locally duplicated LDAP/RADIUS users when SonicOS does not store their passwords. A password set for a user through the firewall management interface makes that user a local user.
- Reduce unnecessary access. Remove unused or inactive accounts, enforce MFA and strong password policies, and enable account lockout. SonicWall also recommends enabling Botnet Protection and Geo-IP Filtering.
- Review exposure and access paths. Check whether SSLVPN is enabled and whether it is reachable from the internet, then review the accounts and access policies that can use it. These checks help identify which systems and credentials need the closest attention.
SonicWall’s notice recommends updating to SonicOS 7.3.0 in the described migration scenario for enhanced protection against brute-force password and MFA attacks. Confirm that recommendation against the live vendor guidance for the specific firewall model before updating.
What if a local administrator account may be compromised?
A potentially compromised local administrator account calls for more than a user-password reset. SonicWall advises reviewing packet captures, logs, MFA settings, and recent configuration changes. Rotate potentially exposed credentials, including LDAP Login/Bind credentials, if they may have been accessible through the compromised account.
Preserve relevant logs and packet captures while investigating so that changes and access can be reviewed. If you find suspicious administrative activity, use your incident-response process to determine what was accessed or altered and whether additional credentials or systems require remediation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

