SonicWall VPN hit with second vulnerability

Image of technical screen displaying system hacked warning
(Image credit: solarseven / Getty Images)

A vulnerability has been found in a SonicWall VPN server, the second VPN-related issue to hit the company in recent months.

Ethical hackers from Dutch company Computest Security discovered the vulnerability which allowed them to take over the server and potentially access the internal company network, exposing sensitive data.

SonicWall offers a variety of VPN clients, aimed at securing corporate networks. However, exploitable vulnerabilities are not features of the best business VPNs, and this isn't the first time SonicWall has had a vulnerability exposed. In October 2024, hackers targeted SonicWall VPNs to spread ransomware.

How was the vulnerability exploited?

The hackers found vulnerabilities at login. A username and password is needed to access the VPN server and start a session. A unique number is then used to identify the session and with every command, the system knows it is this user.

This identifying number should be untraceable – however, the hackers could predict the numbers. This allowed them to impersonate a user and theoretically move through the network without being detected.

Computest Security reported the vulnerabilities to SonicWall and a patch is now available, but the vulnerabilities found highlight the need for more attention to peripheral security such as VPN servers, routers, and firewalls.

What to look for in a business VPN

With many of us working remotely, a business VPN can allow employees to securely access servers, networks, and company information.

Business VPNs provide additional layers of security by encrypting company data and protecting it from cyberattacks. Businesses are prime targets for hackers, with small and medium sized businesses being the most attractive.

Many business VPNs come with additional security features, making them a cost-effective security solution and reducing the amount of hardware required. They often use cloud-based systems and are designed with multiple team members in mind, ensuring everyone can access the same encrypted data and files.

Perimeter 81 | The best business VPN$80 per month

Perimeter 81 | The best business VPN
Perimeter 81 is our #1 business VPN choice, and it offers a wide range of plans for any business type. Its cloud-based system can protect 10 employees or more and it boasts a huge number of intuitive tools. It isn't the cheapest business VPN, costing $80 per month to protect the minimum 10 users. But it also offers a whole security suite, a 30-day money-back guarantee, and dedicated customer service.

Looking beyond VPNs

As well as implementing business VPNs, it is important for businesses to stay on top of their cybersecurity practices. Human error is the leading cause of data breaches, and an IBM report found the average cost of a breach in 2024 was $5 million. Therefore, employee education is vital and investing in cybersecurity awareness and training programmes is an excellent first step.

Having your businesses audited by an independent cybersecurity company can help identify security weaknesses and expose vulnerabilities. It can also improve your relationship with customers, building your reputation as a secure company.

Using tools such as the best password managers is useful as well. They can generate and store complex and unique passwords, ensuring your data is protected. 123456 is the world's most popular password, and weak passwords can be cracked in seconds. Having a strong password is another easy first step to take.

Disclaimer

We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.

George Phillips
Staff Writer

George is a Staff Writer at Tom's Guide, covering VPN, privacy, and cybersecurity news. He is especially interested in digital rights, censorship, data, and the interplay between cybersecurity and politics. Outside of work, George is passionate about music, Star Wars, and Karate.

Read more
Graphic of red warning sign
Critical VPN vulnerabilities continue to impact businesses
Red computer security warning
2.8 million IP addresses being used in brute force attack on VPNs
Graphic of fibre optic cables attacking code
An estimated 46,000 VPN servers are vulnerable to being hijacked
Surfshark graphic of 2024 data breaches
Nearly 700 million American records were leaked in 2024
DeepSeek logo on smartphone in front of computer data
Massive DeepSeek data leak exposes sensitive info for over 1 million users — what you need to know
best business vpn
The best business VPN service in 2025
Latest in VPNs
VPN on phone in front of US flag
43% of Americans use VPNs – should you?
PIA
What is MACE from Private Internet Access?
ExpressVPN
Claim a week of ExpressVPN for free – we don't know when it's going to end
Flag of Iran flying
80% of Iranians are using VPNs to access the internet – but could government restrictions loosen?
VPN on smartphone in front of Pakistan flag
Pakistan has granted its first VPN licenses – but does this guarantee long-term legality?
French flag with silver padlock and chain in front of it
Leading VPNs could leave France due to blocking threats
Latest in News
AMD Radeon RX 9070 XT
Where to buy AMD Radeon RX 9070 and RX 9070 XT — I recommend these retailers in US and UK
(L to R) Noah Centineo as Owen Hendricks, Maddie Hasson as Nichika Lashin in "The Recruit"
Netflix just canceled 'The Recruit' after 2 seasons and I'm stunned
An older woman and man holding a kettlebell in their chest as they squat down in gym class
This workout could reduce insomnia among over 60s, says new study
Nvidia GeForce RTX 5070 Ti
RTX 5070 can't match RTX 4090 performance in new benchmark — despite Nvidia's claims
An Abode home security menu on a TV screen
Abode now lets you check in on your smart home security system right from your Apple TV
Maria Debska in Harlan Coben's Just One Look
Netflix top 10 shows — here's the 3 worth watching right now