Cybersecurity Blog | RedLegg

Security Bulletin: Multiple Vulnerabilities affecting SMA1000 Series Appliances

Written by RedLegg's Cyber Threat Intelligence Team | 9/3/26, 7:15 PM

About:

SonicWall has disclosed two vulnerabilities affecting SMA1000 series appliances, including CVE-2026-83548, a critical pre-authentication SSRF vulnerability that is actively exploited and listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Successful exploitation can provide unauthorized access to sensitive functionality, while a related command injection flaw (CVE-2026-83549) may enable remote code execution after administrative access is obtained. Organizations should immediately apply the latest hotfixes and assess affected appliances for signs of compromise.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.

VULNERABILITIES

Pre-Authentication SSRF via Unintended Forward-Proxy in SonicWall SMA1000 Series Appliances

 

Identifier: CVE-2026-83548 
PoC or Exploitation: Confirmed actively exploited. SonicWall PSIRT states it has investigated a case indicating active exploitation of the vulnerabilities described in its advisory. It is listed in the CISA Known Exploited Vulnerabilities catalog.
CVSS Score: 10.0 (Critical, CVSS v3.0)

Update / Patch:
SonicWall has released a fixed hotfix version addressing this vulnerability. No workaround is available.

Affected versions include:

  • SMA1000 models 6210, 7210, and 8200v running platform-hotfix version 12.4.3-03453 or older
  • SMA1000 models 6210, 7210, and 8200v running platform-hotfix version 12.5.0-02835 or older

Fixed versions include:

  • Platform-hotfix version 12.4.3-03526 or higher
  • Platform-hotfix version 12.5.0-02952 or higher

This vulnerability does not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. The latest hotfix is available via mysonicwall.com.

SonicWall Security Advisory SNWLID-2026-0016:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

Description:
CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability in the Appliance Work Place interface of SonicWall SMA1000 series appliances.

An unintended alternate access path causes the appliance to function as an unintended forward proxy. A remote unauthenticated attacker can exploit this to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Mitigation Recommendation:
Upgrade to the applicable fixed hotfix version immediately.

Contact SonicWall Technical Support to review affected systems for indicators of compromise.

If indicators of compromise are found, re-image physical appliances or re-deploy virtual appliances.

Post-Authentication OS Command Injection in SonicWall SMA1000 Appliance Management Console

 

Identifier: CVE-2026-83549
PoC or Exploitation:
Confirmed actively exploited. SonicWall PSIRT states it has investigated a case indicating active exploitation of the vulnerabilities described in its advisory.
CVSS Score: 7.8 (High, CVSS v3.0)

Update / Patch:
SonicWall has released a fixed hotfix version addressing this vulnerability. No workaround is available.

Affected versions include:

  • SMA1000 models 6210, 7210, and 8200v running platform-hotfix version 12.4.3-03453 or older
  • SMA1000 models 6210, 7210, and 8200v running platform-hotfix version 12.5.0-02835 or older

Fixed versions include:

  • Platform-hotfix version 12.4.3-03526 or higher
  • Platform-hotfix version 12.5.0-02952 or higher

This vulnerability does not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. The latest hotfix is available via mysonicwall.com.

SonicWall Security Advisory SNWLID-2026-0016:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

Description:
CVE-2026-83549 is a post-authentication OS command injection vulnerability in the Appliance Management Console of SonicWall SMA1000 series appliances.

Under specific conditions, a remote attacker who has already authenticated as an administrator can exploit this vulnerability to execute arbitrary OS commands, resulting in remote code execution. This vulnerability requires prior administrator-level access to exploit.

Mitigation Recommendation:
Upgrade to the applicable fixed hotfix version immediately.

Restrict and closely monitor administrator-level access to the Appliance Management Console since exploitation requires an attacker to already hold administrator credentials or session access.

Contact SonicWall Technical Support to review affected systems for indicators of compromise.

If indicators of compromise are found, re-image physical appliances or re-deploy virtual appliances.