CVE-2025-40604
CRITICALDescription
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Is your site exposed to CVE-2025-40604?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sonicwall | email_security_appliance_5000_firmware |
| sonicwall | email_security_appliance_5000 |
| sonicwall | email_security_appliance_5050_firmware |
| sonicwall | email_security_appliance_5050 |
| sonicwall | email_security_appliance_7000_firmware |
| sonicwall | email_security_appliance_7000 |
| sonicwall | email_security_appliance_7050_firmware |
| sonicwall | email_security_appliance_7050 |
| sonicwall | email_security_appliance_9000_firmware |
| sonicwall | email_security_appliance_9000 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-40604? +
How severe is CVE-2025-40604? +
What products are affected by CVE-2025-40604? +
How do I check if I'm vulnerable to CVE-2025-40604? +
Related Vulnerabilities
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary …
iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These …
stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If …
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or …
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and …
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation …