Firewall
SonicWall

SonicWall TZ370

02-SSC-6447 - SonicWall TZ370 next-generation firewall for small business.

SonicWall TZ370

Specifications

UTM
Yes
VPN
IPSec, SSL
Ports
8x Gigabit
Throughput
4 Gbps

Potential Threats

5
Critical
13
High
16
Medium
0
Low

34 Known CVEs

5 critical vulnerabilities found — immediate patching required.
13 high-severity vulnerabilities — patch as soon as possible.
Audit firewall rules and remove unused allow entries. Enable detailed logging. Restrict management access to trusted IPs only.

Default IP

192.168.168.168

Default admin panel address for SonicWall TZ370

Default Credentials — SonicWall TZ370

Username Password Access Type Protocol Port Notes
web HTTPS 443

Known CVE Vulnerabilities (34)

Sort:
CVE-2026-3439 2026

A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

4.9
CVE-2026-0402 2026

A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

4.9
CVE-2026-0401 2026

A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

4.9
CVE-2026-0400 2026

A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

4.9
CVE-2026-0399 2026

Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API...

4.9
CVE-2025-40601 2025

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), w...

7.5
CVE-2025-40600 2025

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service di...

9.8
CVE-2024-53704 2025

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

9.8
CVE-2024-40766 2024

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource...

9.8
CVE-2024-40764 2024

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

7.5

Showing 10 of 34

FAQ

What is the default password for SonicWall TZ370?

The most common default credentials for SonicWall TZ370 are listed in the table above. Always change these immediately after setup.

What is the default username for SonicWall TZ370?

The default username for SonicWall TZ370 is typically "admin". The full list of default credentials including username, password, access type and port is shown in the table on this page.

How do I change the password on SonicWall TZ370?

Log in to the admin panel using the default credentials listed above. Navigate to Administration → Password or System → Account settings. Enter the current password and set a new strong password. Save the changes.

How do I reset SonicWall TZ370 to factory defaults?

Locate the Reset button (usually a small pinhole on the back/bottom of the device). Hold it for 10-30 seconds while powered on until the LEDs flash. The device will reboot with default settings.

Is it safe to leave default credentials unchanged?

No. Default credentials are publicly known and frequently exploited by automated scanners. Change the admin password immediately after first login.

Does SonicWall TZ370 have known security vulnerabilities?

SonicWall TZ370 has 34 known CVE vulnerabilities documented in our database. The full list with severity ratings is shown on this page. Apply the latest firmware update from the manufacturer to address known issues.

Related Devices