CVE-2025-32818

Published Apr 23, 2025

Last updated 2 months ago

Overview

Description
A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.
Source
PSIRT@sonicwall.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

PSIRT@sonicwall.com
CWE-476

Social media

Hype score
Not currently trending
  1. jon williams of @bishopfox isn't on X, so I can brag on him here 🙂 he recently entered the SonicWall Hall of Fame (https://t.co/S6rhJbqPEw) for discovering and reporting CVE-2025-32818, joining the ranks of other great hackers like @AlizTheHax0r @mwulftange @wvuuuuuuuuuuuuu ht

    @noperator

    28 Apr 2025

    941 Impressions

    2 Retweets

    21 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️Vulnerabilidades en los productos SonicWall ❗CVE-2025-32818 ➡️Más info: https://t.co/wkT9EXJYMi https://t.co/r2YoOXAkt0

    @CERTpy

    25 Apr 2025

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2025-32818 🔴 HIGH (7.5) 🏢 SonicWall - SonicOS 🏗️ 7.1.1-7040 🔗 https://t.co/IYNbRyzNZx #CyberCron #VulnAlert #InfoSec https://t.co/45KWoMcmEf

    @cybercronai

    25 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨Alert🚨 CVE-2025-32818 : SonicOS SSLVPN Null Pointer Dereference Denial-of-Service (DoS) Vulnerability 📊15.5K+ Services are found on the https://t.co/ysWb28Crld yearly. 🔗Hunter Link:https://t.co/7lZnlpIarI 👇Query HUNTER : https://t.co/q9rtuGgxk7="SonicOS" https://t.co/I6Hs7x

    @HunterMapping

    24 Apr 2025

    1109 Impressions

    7 Retweets

    13 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  5. 【早期警戒脆弱性情報】 CVE番号:CVE-2025-32818 SonicOS SSLVPN Virtual Office インターフェースに Null ポインタ逆参照の脆弱性があるため、認証されていないリモートの攻撃者がファイアウォールをクラッシュさせ、サービス拒否 (DoS) 状態を引き起こす可能性があります。 https://t.co/DFiGtht5VH

    @SMBC_cyberfront

    24 Apr 2025

    129 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-32818 A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially l… https://t.co/erZNLiGq2Y

    @CVEnew

    23 Apr 2025

    495 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.