Hackers Bypass MFA on Outdated SonicWall VPNs Using LDAP Flaw, Researchers Say

Last updated: May 21, 2026 Reading time: 4 minutes
Disclosure
Share
Hackers Bypass MFA on Outdated SonicWall VPNs Using LDAP Flaw, Researchers Say
  • Hackers brute-forced VPN logins, bypassing MFA entirely on outdated Gen6 SonicWall SSL-VPN apps.
  • Updating firmware alone can’t fix the security flaw. Admins must manually reconfigure LDAP to truly close the hole.
  • Attackers moved from VPN to internal servers in under an hour. Logs showed normal MFA flows, hiding the breach.

A patch does not always mean you are safe. And SonicWall just learned that lesson the hard way.

Between February and March, hackers broke into multiple networks using a flaw that many people thought they had already fixed.

Updates Aren’t Fixing It

Take CVE-2024-12802, for example. It’s a bug found in SonicWall’s Gen6 SSL-VPN devices. Those devices don’t enforce MFA for the UPN login format. This allows an attacker with valid credentials (which they can brute-force) to just walk right in. No second factor needed.

SonicWall has rolled out a firmware update. But just installing can’t fix the problem completely. The company has warned admins in a security advisory. You also have to manually reconfigure your LDAP server. If you don’t? The MFA stays broken.

Researchers at ReliaQuest responded to multiple intrusions this spring. They saw devices running the updated firmware. Yet those same devices remained vulnerable. The admins had skipped the manual steps.

ReliaQuest has high confidence that this is the first time someone has used this exploit in the wild. The targets spanned multiple sectors and countries. In one incident, the hacker moved pretty fast. They got into the internal network, then made it a domain-joined file server. How long did that take them? Just thirty minutes.

From there, they used a shared local admin password to set up a remote RDP connection. They tried to drop a Cobalt Strike beacon (a tool for command-and-control). They also tried to load a vulnerable driver. That driver likely aimed to kill endpoint protection using the BYOVD trick.

But an EDR system blocked both the beacons. Also blocked the driver. That was how the attack stopped.

So Who is Coordinating These Attacks? 

The hacker did not act like a typical ransomware crew. They logged in, looked around, tested credentials, and then logged out. They came back days later, sometimes using different accounts.

ReliaQuest believes this is an access broker. They sell the keys to the kingdom to other threat groups.

Last year, the Akira ransomware gang hit SonicWall VPNs. They logged in despite MFA being on. No one confirmed the method back then. This new finding might explain how.

How to Truly Fix the Security Hole

Gen6 devices are old. Like, really old. They reached end-of-life on April 16 this year. They no longer get security updates. You really should move to Gen7 or Gen8. On those newer boxes, a simple firmware update kills the vulnerability for good.

Security best practices are evolving elsewhere too. Apple and Google’s new RCS encryption ensures cross-platform messaging is protected, a reminder that modern security requires proactive implementation, not just patching old systems.

But if you are stuck on Gen6, you must follow all the steps. Here is the full checklist from SonicWall:

Delete the old LDAP config that uses userPrincipalName in the Qualified login name field. Then remove any locally cached LDAP users.

Next, remove the SSL VPN ‘User Domain’ that’s been configured. This reverts to LocalDomain.

Afterwards, reboot the firewall and recreate the LDAP config without userPrincipalName. Finally, make a fresh backup. Do not restore an old, vulnerable config later.

Sneaky Logs and Red Flags

Here is the worst part. The fake logins still looked like normal MFA flows in the logs. Defenders saw what appeared to be a successful second factor check. But it had never actually happened.

ReliaQuest found one clear signal: sess=”CLI” in the logs. That suggests scripted or automated VPN authentication. Watch for it.

Other red flags include event IDs 238 and 1080. Also, watch for VPN logins coming from sketchy VPS or VPN infrastructure.

So if you run a Gen6 SonicWall, do not just trust the firmware version. Check your LDAP config today. Otherwise, that MFA prompt you see? It might be lying to you.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts