CVE-2025-32818

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 476

Summary

CVE-2025-32818 is a Null Pointer Dereference vulnerability that affects the SonicOS SSLVPN Virtual office interface. An unauthenticated attacker can exploit this flaw to cause a crash in the firewall, potentially triggering a Denial-of-Service (DoS) condition. The vulnerability is located in the interface, and an attacker does not need to be authorized to exploit it. Successful exploitation can result in the firewall becoming unresponsive, rendering it unable to perform its intended function of securing the network. Organizations using SonicOS SSLVPN are advised to apply the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share