SonicWall has disclosed two vulnerabilities in its SMA1000 series secure-access appliances (models
6210, 7210 and 8200v) and confirmed they are being exploited in the wild. The more serious, CVE
2026-83548, is a maximum-severity (CVSS 10.0) pre-authentication server-side request forgery flaw in
the appliance’s Work Place interface that lets a remote, unauthenticated attacker reach sensitive
functionality and perform unauthorised operations; the second, CVE-2026-83549, is a high-severity OS
command-injection flaw in the management console that an administrator-authenticated attacker can
use to run arbitrary commands. There is no workaround, but SonicWall has released hotfixes, and
because exploitation is already occurring, every affected SMA1000 appliance should be upgraded
immediately and reviewed for signs of compromise. These issues do not affect SonicWall firewall SSL
VPN or the SMA 100 series.
1. Vulnerability Details
CVE ID – CVE-2026-83548, CVE-2026-83549 (SonicWall advisory SNWLID-2026-0016)
CVSS SCORE – 10.0 (CVE-2026-83548); 7.8 (CVE-2026-83549)
EXPLOIT STATUS – Confirmed exploited in the wild by SonicWall PSIRT and Sophos (advisory published 1 Sep
2026). No workaround; hotfixes available.
SonicWall disclosed two vulnerabilities in its SMA1000 secure-access appliances that can be chained: an
unauthenticated attacker can reach internal functionality via the SSRF, and an administrator-authenticated attacker can
achieve remote code execution via the command-injection flaw.
CVE-2026-83548 (CVSS 10.0, pre-auth SSRF): A pre-authentication server-side request forgery in the SMA1000
Work Place interface, caused by an unintended alternate access path acting as a forward proxy (CWE-918, CWE
441). A remote unauthenticated attacker could gain unauthorised access to sensitive functionality and perform
unauthorised operations. Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
CVE-2026-83549 (CVSS 7.8, post-auth RCE): A post-authentication OS command-injection flaw in the Appliance
Management Console (AMC) from improper neutralisation of special elements (CWE-78). In specific conditions a
remote attacker authenticated as administrator could execute arbitrary OS commands, resulting in remote code
execution. Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
2. Affected Products & Fixed Versions
| Component | Vulnerable Versions | Fixed Build |
| SMA1000 6210, 7210, 8200v | 12.4.3-03453 and older | 12.4.3-03526 and higher |
| SMA1000 6210, 7210, 8200v | 12.5.0-02835 and older | 12.5.0-02952 and higher |
3. Exploitation Status
SonicWall PSIRT has investigated a case indicating active exploitation of these vulnerabilities.
- Active exploitation: SonicWall confirms exploitation in the wild and strongly urges customers to apply the hotfix immediately; Sophos Counter Threat Unit corroborates the active-exploitation status. There is no workaround.
- Scope: The flaws affect only SMA1000 appliances (6210, 7210, 8200v). They do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 series product line. Hotfixes are available on mysonicwall.com.
4. Recommendations
- Upgrade all SonicWall SMA1000 appliances (6210, 7210 and 8200v), physical or virtual, to the fixed hotfix immediately (12.4.3-03526 or higher, or 12.5.0-02952 or higher) via mysonicwall.com. There is noworkaround and both flaws are under active exploitation.
- Assume potential compromise: contact SonicWall Technical Support to review each appliance for indicators of compromise, given confirmed in-the-wild exploitation of a pre-authentication CVSS 10.0 flaw.
- If any indicators of compromise are found, follow SonicWall’s guidance: re-image (hardware) or re-deploy (virtual) the appliance, change all user and administrator passwords, and reset all TOTP tokens.
- Reduce exposure while remediating: restrict Appliance Management Console access to trusted administrative networks, limit internet exposure of the Work Place interface, and monitor appliance and authentication logs for anomalous requests, unexpected administrator actions and command execution.
- Track the SonicWall PSIRT advisory (SNWLID-2026-0016) and CISA KEV for any published indicators of compromise, and confirm that no SMA1000 appliances remain on affected builds (12.4.3-03453 or 12.5.002835 and older).
5. Sources
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
- https://www.sophos.com/en-us/blog/sonicwall-83548-83549
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.