Back to feed

SonicWall warns of two exploited SMA1000 zero-days

2 min
SonicWall warns of two exploited SMA1000 zero-days

This digest was compiled by AI from multiple sources — links to the originals are below.

SonicWall disclosed two zero-day vulnerabilities in its SMA1000 secure remote access appliances that have been exploited in the wild. The flaws, CVE-2026-83548 and CVE-2026-83549, affect models 6210, 7210, and 8200v and can be chained for remote code execution. The company urges customers to apply hotfixes 12.4.3-03526 and 12.5.0-02952 or higher.

Key Facts

  • CVE-2026-83548 has a CVSS score of 10 and is a pre-authentication SSRF issue in the Appliance Work Place interface.
  • CVE-2026-83549 has a CVSS score of 7.8 and is an OS command injection flaw in the Appliance Management Console.
  • SonicWall observed exploitation of both vulnerabilities, suggesting they are chained in attacks.
  • Shadowserver tracks over 400 SMA1000 appliances exposed online, though some may already be patched.
  • CISA's Known Exploited Vulnerabilities catalog includes 17 SonicWall product flaws, but the two new CVEs have not yet been added.

Vulnerability Details

CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the Appliance Work Place interface of SMA1000 appliances. It carries a CVSS score of 10 and can be exploited remotely without authentication to access sensitive functionality and conduct unauthorized operations. CVE-2026-83549 is an OS command injection vulnerability in the Appliance Management Console (AMC) component. With a CVSS score of 7.8, it allows an authenticated attacker to execute arbitrary OS commands, potentially leading to remote code execution.

Affected Products and Remediation

The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v. Hotfixes 12.4.3-03526 and 12.5.0-02952, and higher versions, patch the flaws. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected. SonicWall PSIRT has investigated a case indicating active exploitation and strongly urges customers to upgrade to the hotfix release as soon as possible.

Exploitation and Exposure

SonicWall noted in its advisory that it has observed exploitation of both vulnerabilities, suggesting they have been chained in attacks. No details are available on the attacks exploiting CVE-2026-83548 and CVE-2026-83549, and the vendor's public advisory does not include indicators of compromise. Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain. CISA's Known Exploited Vulnerabilities catalog includes 17 SonicWall product flaws, but CVE-2026-83548 and CVE-2026-83549 have not yet been added.

2 sources

Time · lag behind first