Open Nav
Sign Up

SonicWall SMA1000 Zero-Days CVE-2026-83548 and CVE-2026-83549 Exploited for Unauthenticated RCE

sonicwall sma1000_cve-2026-83548-83549

Filip Dimitrov

September 6, 2026

SonicWall has disclosed two actively exploited zero-day vulnerabilities affecting its SMA1000 secure remote access appliances. The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect the SMA1000 Work Place interface and Appliance Management Console (AMC) respectively.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on September 2, 2026, one day after disclosure. CISA also designated both vulnerabilities as requiring forensic triage.

Vulnerability Overview

CVEVulnerabilityCVSSExploitation
CVE-2026-83548Pre-authentication SSRF / unintended forward proxy10.0 CriticalActively exploited
CVE-2026-83549OS command injection / remote code execution7.8 HighActively exploited

CVE-2026-83548: Pre-Authentication SSRF

CVE-2026-83548 exists in the SMA1000 Appliance Work Place interface and results from an unintended alternate access path that effectively exposes forward-proxy functionality.

An attacker does not require authentication or user interaction to exploit the vulnerability. A remote attacker capable of reaching the affected interface may abuse the flaw to access sensitive functionality and perform operations that should not normally be accessible from the external network.

The vulnerability has been assigned a maximum CVSS v3.1 score of 10.0. Its classification includes server-side request forgery weaknesses CWE-918 and CWE-441. 

The security significance of SSRF on a VPN or remote access appliance goes beyond ordinary web-server SSRF. These devices commonly expose an external web interface while simultaneously communicating with internal management services and trusted network resources.

An attacker who can cause the appliance to issue arbitrary internal requests may therefore cross an important trust boundary and reach functionality that would otherwise only be accessible locally or from trusted network locations.

CVE-2026-83549: OS Command Injection and RCE

CVE-2026-83549 affects the SMA1000 Appliance Management Console (AMC).

The vulnerability results from improper neutralization of special elements used in an operating system command, classified as CWE-78: OS Command Injection.

Under normal conditions, exploitation requires authenticated administrative access and specific system conditions. Successful exploitation allows arbitrary operating-system commands to be executed on the appliance, resulting in remote code execution.

Although the vulnerability receives a lower individual score of 7.8 because of its privilege requirements, its risk changes considerably when considered alongside CVE-2026-83548.

The SSRF vulnerability may allow an attacker to reach the functionality necessary to trigger CVE-2026-83549, potentially eliminating the authentication barrier and producing an unauthenticated RCE chain.

How the Vulnerability Chain Works

At a high level, the potential attack chain consists of four stages.

1. The Attacker Reaches the Work Place Interface

An attacker targets an internet-accessible SMA1000 appliance running a vulnerable firmware version.

No existing account or user interaction is required to begin exploiting CVE-2026-83548.

2. SSRF Crosses the Appliance Trust Boundary

CVE-2026-83548 allows the attacker to abuse unintended proxy functionality to interact with sensitive functionality that would not ordinarily be exposed externally.

Instead of directly attacking the protected management component, requests can potentially be routed through the appliance itself.

3. Management Functionality Becomes Reachable

The attacker may then use this access path to reach functionality associated with the Appliance Management Console.

This is significant because CVE-2026-83549 is normally constrained by its authentication requirements.

4. OS Commands Are Executed

The command injection weakness can then potentially be triggered to execute arbitrary operating-system commands.

The result is an attack chain that begins with an unauthenticated request from the internet and may end with code execution on the SMA1000 appliance.

SMA1000 Appliances Were Already Targeted by Zero-Days in July

The September vulnerabilities are especially concerning because they follow another major compromise campaign against the same SMA1000 product family less than two months earlier.

In July 2026, SonicWall disclosed:

  • CVE-2026-15409 – CVSS 10.0 pre-authentication SSRF
  • CVE-2026-15410 – high-severity command/code injection

Those vulnerabilities were also chained by attackers to compromise internet-facing SMA1000 appliances and achieve root-level command execution.

Affected and Fixed Versions

SonicWall lists the following appliances as affected:

  • SMA 6210
  • SMA 7210
  • SMA 8200v
  • 8200v deployments across supported hypervisors

The vulnerable and fixed firmware versions are:

Firmware BranchVulnerableFixed
12.4.312.4.3-03453 platform-hotfix and earlier12.4.3-03526 or later
12.5.012.5.0-02835 platform-hotfix and earlier12.5.0-02952 or later

SonicWall instructs all organizations operating affected physical or virtual SMA1000 appliances to upgrade to the latest hotfix immediately.

Recommended Mitigation and Response

1. Patch SMA1000 Appliances Immediately

Upgrade affected systems to at least:

12.4.3 branch

  • 12.4.3-03526 platform-hotfix

12.5.0 branch

  • 12.5.0-02952 platform-hotfix

or any later SonicWall-approved release.

Organizations that applied the July SMA1000 hotfixes should verify their version again, as those releases do not protect against the newly disclosed vulnerabilities.

2. Investigate Previously Exposed Appliances

Patching prevents future exploitation but cannot reverse a compromise that occurred while the appliance was vulnerable.

Because SonicWall confirmed exploitation before public disclosure, internet-facing appliances running affected versions should be treated as candidates for compromise and reviewed accordingly.

3. Contact SonicWall for IOC Review

SonicWall specifically instructs affected organizations to contact Technical Support for assistance reviewing systems for indicators of compromise.

Given the current lack of comprehensive public IOCs, this is particularly important for organizations with exposed appliances.

4. Re-Image or Redeploy Compromised Appliances

If evidence of compromise is identified, SonicWall recommends:

  • re-imaging physical appliances;
  • redeploying virtual appliances.

Simply removing an observed malicious file should not be considered sufficient where an attacker may have obtained command execution on the appliance.

5. Rotate Credentials and MFA Secrets

Following confirmed compromise, SonicWall instructs organizations to:

  • change all user passwords;
  • change all administrator passwords;
  • reset TOTP tokens.

This step is critical because a compromised remote-access appliance may expose authentication material to the attacker.

Stay Safe. Stay Secure.

OP Innovate Research Team

Under Cyber Attack?

Fill out the form and we will contact you immediately.