CVE-2025-40604 is a critical "Download of Code Without Integrity Check" vulnerability affecting multiple SonicWall Email Security appliance models. This flaw allows attackers with VMDK or datastore access to modify system files, leading to persistent arbitrary code execution due to the appliance loading root filesystem images without signature verification. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk as it requires no user interaction and can be exploited remotely, resulting in complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.33.8195CPE matchmatch criteria | cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:* | ||
<= 10.0.33.8195CPE matchmatch criteria | cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:* | ||
<= 10.0.33.8195CPE matchmatch criteria | cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:* | ||
<= 10.0.33.8195CPE matchmatch criteria | cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:* | ||
<= 10.0.33.8195CPE matchmatch criteria | cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.