CVE-2024-53704

CRITICAL KEV RANSOMWARE NUCLEI

SonicOS >=7.1.1-7040 <7.1.1-7058 - Unauthenticated Authentication Bypass via SSLVPN

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-53704 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 18, 2025, with confirmed use in ransomware campaigns. EIP tracks 4 public exploits from researchers including istagmbh, anir0y, spicy-bear. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits CVE-2024-53704, an authentication bypass vulnerability in SonicWALL NetExtender VPN. It skips the login process by injecting a stolen 'swap' cookie and establishes a VPN session, allowing unauthorized access to the VPN tunnel.

Description

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Exploits (4)

nomisec WORKING POC 2 stars
by istagmbh · remote
https://github.com/istagmbh/CVE-2024-53704

This PoC exploits CVE-2024-53704, an authentication bypass vulnerability in SonicWALL NetExtender VPN. It skips the login process by injecting a stolen 'swap' cookie and establishes a VPN session, allowing unauthorized access to the VPN tunnel.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: SonicWALL NetExtender VPN (Linux/macOS clients)
No auth needed
Prerequisites: Valid 'swap' cookie from an active session · Network access to the target VPN server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by anir0y · remote
https://github.com/anir0y/sonicwall-audit-toolkit

This repository contains a functional exploit for CVE-2024-53704, an authentication bypass vulnerability in SonicWall SSLVPN via cookie forgery. It includes a Docker-based lab environment with vulnerable containers for testing, along with working exploit code and detailed walkthroughs.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: SonicWall SSLVPN
No auth needed
Prerequisites: access to the SSLVPN login page · ability to forge session cookies
devstral-2 · analyzed Feb 23, 2026 Full analysis →
github WORKING POC
by spicy-bear · pythonpoc
https://github.com/spicy-bear/cve_exploits/tree/main/cve-2024-53704.py

The repository contains functional exploit code for CVE-2024-53704, targeting a session hijacking vulnerability in a web application via a crafted cookie. The exploit sends a GET request with a base64-encoded cookie to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Unknown (likely a web application with SSL VPN functionality)
No auth needed
Prerequisites: Network access to the target · Target service running on port 4433 (or specified port)
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by sfewer-r7 · remote
https://github.com/sfewer-r7/SonicSessionLeak

This PoC exploits CVE-2024-53704 by brute-forcing session cookies to leak valid session IDs from a target system. It uses a checksum calculation to generate valid cookies and checks their validity via an API endpoint.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Unknown (likely a web application with session management vulnerabilities)
No auth needed
Prerequisites: Network access to the target · Target API endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

SSL VPN Session Hijacking
CRITICALVERIFIEDby johnk3r
Shodan: http.html_hash:-1466805544

Scores

CVSS v3 9.8
EPSS 0.9386
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2025-02-18
VulnCheck KEV 2025-02-13
ENISA EUVD EUVD-2024-52037
Ransomware Use Confirmed
CWE
CWE-287
Status published
Products (3)
sonicwall/sonicos 7.1.2-7019
sonicwall/sonicos 8.0.0-8035
sonicwall/sonicos 7.1.1-7040 - 7.1.1-7058
Published Jan 09, 2025
KEV Added Feb 18, 2025
Tracked Since Feb 18, 2026