Over 25,000 SonicWall VPN Firewalls exposed to critical flaws

Share:

Over 25,000 publicly accessible SonicWall SSLVPN devices are vulnerable to critical severity flaws, with 20,000 using a SonicOS/OSX firmware version that the vendor no longer supports.

These results come from an analysis conducted by cybersecurity firm Bishop Fox, which was motivated by a series of important vulnerabilities disclosed this year impacting SonicWall devices.

Vulnerabilities affecting SonicWall SSL VPN devices were recently exploited by ransomware groups, including Fog ransomware and Akira, as they are an attractive target for gaining initial access to corporate networks.

Massive attack surface

By leveraging internet scanning tools like Shodan and BinaryEdge and its proprietary fingerprinting techniques, Bishop Fox identified 430,363 publicly exposed SonicWall firewalls.

Public exposure means that the firewall’s management or SSL VPN interfaces are accessible from the internet, presenting an opportunity for attackers to probe for vulnerabilities, outdated/unpatched firmware, misconfigurations, and brute-force weak passwords.

“The management interface on a firewall should never be publicly exposed, as this presents an unnecessary risk,” explains BishopFox.

“The SSL VPN interface, although designed to provide access to external clients over the internet, should ideally be protected by source IP address restrictions.”

When looking into the firmware versions used on those devices, the researchers discovered that 6,633 use Series 4 and 5, both of which reached the end of life (EoL) years ago. Another 14,077 use no longer supported versions of the now partially supported Series 6.

Support status by Series
Support status by SonicOS version
Source: BishopFox

This results in 20,710 devices running end-of-life firmware being vulnerable to many public exploits, but this figure is not representative of the accurate scale of the problem.

BishopFox also found 13,827 running unknown firmware versions, 197,099 running unsupported Series 6 firmware, but for which it was impossible to determine the exact version, and another 29,254 running an unknown version of Series 5 firmware.

When looking into the scan results using fingerprinting technology to identify the specific firmware versions and their protection against known vulnerabilities, the researchers determined that 25,485 are vulnerable to critical severity issues and 94,018 to high severity flaws.

Devices vulnerable to known flaws
Devices vulnerable to known flaws
Source: BishopFox

Most of the devices confirmed to be vulnerable are on the Series 7 firmware but have not been updated to the latest version, which closes security gaps.

While the total of 119,503 vulnerable endpoints is an improvement over the 178,000 found vulnerable to DoS and RCE attacks in January 2024, it’s still indicative of slow patch adoption.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:21 pm, Jun 9, 2025
weather icon 18°C
L: 18° | H: 20°
broken clouds
Humidity: 59 %
Pressure: 1021 mb
Wind: 9 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 82%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 20°°C 0.2 mm 20% 9 mph 75 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 20°°C 0.8 mm 80% 11 mph 83 % 1020 mb 0 mm/h
Wed Jun 11 10:00 pm
weather icon
13° | 23°°C 0.2 mm 20% 12 mph 81 % 1021 mb 0 mm/h
Thu Jun 12 10:00 pm
weather icon
15° | 25°°C 1 mm 100% 10 mph 81 % 1018 mb 0 mm/h
Fri Jun 13 10:00 pm
weather icon
16° | 27°°C 1 mm 100% 11 mph 93 % 1020 mb 0 mm/h
Today 1:00 pm
weather icon
18° | 19°°C 0.2 mm 20% 8 mph 58 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
19° | 19°°C 0 mm 0% 8 mph 57 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
18° | 18°°C 0 mm 0% 8 mph 60 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 9 mph 75 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 14°°C 0 mm 0% 9 mph 81 % 1018 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 13°°C 0 mm 0% 11 mph 83 % 1017 mb 0 mm/h
Tomorrow 7:00 am
weather icon
14° | 14°°C 0 mm 0% 10 mph 83 % 1017 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 10 mph 82 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€94,102.85
1.74%
Ethereum(ETH)
€2,222.92
1.19%
Tether(USDT)
€0.88
0.01%
XRP(XRP)
€1.98
2.07%
Solana(SOL)
€136.29
4.30%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.162933
1.60%
Shiba Inu(SHIB)
€0.000011
1.51%
Pepe(PEPE)
€0.000011
4.33%
Peanut the Squirrel(PNUT)
€0.237424
5.93%
Scroll to Top