HomeDefault status
unknown
6.5.4.15-117n and older versions
affected
7.0.1-5161 and older version
affected
7.1.2-7019
affected
8.0.0-8035
affected
Description
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
Problem types
CWE-134 Use of Externally-Controlled Format String
Product status
6.5.4.15-117n and older versions
7.0.1-5161 and older version
7.1.2-7019
8.0.0-8035
Credits
Catalpa of DBappSecurity Co. Ltd.
References
psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0004