news.mlab.sh
Back to the feed
vulnerability

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

CriticalCVSS 10.0
Summary

SonicWall has disclosed two zero-day vulnerabilities in its SMA 1000 perimeter devices, allowing unauthenticated remote code execution (RCE). Attackers are actively exploiting these flaws, and SonicWall urges customers to immediately upgrade to the latest firmware to prevent further exploitation. The vulnerabilities target the appliance management console and user-facing portal, and are particularly concerning due to the device's role as a network edge gateway.

SonicWall has disclosed two zero-day vulnerabilities affecting select SMA 1000 perimeter devices, enabling unauthenticated remote code execution (RCE). Attackers are currently exploiting these flaws, and SonicWall is urging customers to patch immediately to mitigate the risk. The vulnerabilities target the SMA 1000 Appliance Work Place interface (user-facing portal) and the SMA 1000 Appliance Management Console (AMC) (administrator portal).

CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) vulnerability, carries a CVSS score of 10. This allows a remote, unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVE-2026-83549, a post-authentication OS Command Injection vulnerability, has a CVSS score of 7.8, enabling an authenticated remote attacker to execute arbitrary OS commands, leading to RCE.

Rapid7 noted that these vulnerabilities can be chained together to achieve unauthenticated RCE on affected appliances. SonicWall’s Product Security Incident Response Team (PSIRT) investigated a case indicating active exploitation of these vulnerabilities. The vulnerabilities were internally discovered by William Perry and Adam Babis at SonicWall.

The affected models are SMA 1000 models 6210, 7210, and 8200v, specifically running versions 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. SonicWall recommends upgrading to 12.4.3-03526/12.5.0-02952 (platform-hotfix) and higher.

Due to the role of SMA 1000 appliances as network edge gateways, frequently exposed directly to the internet, successful exploitation is particularly concerning. SonicWall advises compromised customers to re-image hardware appliances or re-deploy virtual appliances, change all user and administrator passwords, and reset TOTP tokens to mitigate potential damage.

Read the full article at Dark Reading