Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN897
_____________________________________________________________________

DATE                : 16/09/2026

HARDWARE PLATFORM(S): SonicWall SMA1000 Series Appliances.

OPERATING SYSTEM(S):  SonicWall SMA1000 Series Appliances software.
  
=====================================================================
https://psirt.global.sonicwall.com/vuln-list
_____________________________________________________________________

SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities

10

Overview

Advisory ID             SNWLID-2026-0016
First Published         2026-09-01
Last Updated            2026-09-01
Workaround              false
Status                  Applicable
CVE                     CVE-2026-83548, CVE-2026-83549
CWE                     CWE-918, CWE-441, CWE-78
CVSS v3                 10.0
CVSS Vector             CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Direct Link

Summary

1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy

A Pre-authentication SSRF vulnerability exists in the SMA1000
Appliance Work Place interface due to an unintended alternate
access path. A remote unauthenticated attacker could potentially
exploit this vulnerability to gain unauthorized access to
sensitive functionality and perform unauthorized operations..

CVSS Score: 10.0
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-918: Server-Side Request Forgery (SSRF)
CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')

2) CVE-2026-83549 - Post-authentication Remote Code Execution(
RCE) Vulnerability

Post-authentication Improper Neutralization of Special Elements
used in an OS Command ('OS Command Injection') vulnerability has
been identified in the SMA1000 Appliance Management Console (AMC)
which in specific conditions could potentially enable a remote
authenticated attacker as administrator to execute arbitrary OS
commands, resulting in remote code execution.

CVSS Score: 7.8
CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78: Improper Neutralization of Special Elements used in an
OS Command ('OS Command Injection')

IMPORTANT: SonicWall PSIRT has investigated a case indicating the
active exploitation of the vulnerabilities described in this
advisory. Customers are strongly urged to upgrade to the hotfix
release as soon as possible to remediate this vulnerability.


Affected Product(s)

Affected Product    Affected Version(s)

SMA1000 Models - 6210, 7210, 8200v 
   12.4.3-03453 (platform-hotfix) and older versions.
   12.5.0-02835 (platform-hotfix) and older versions. 

Note: These vulnerabilities do not affect SSL-VPN running on
SonicWall firewalls or the SMA 100 Series product line.

The latest platform-hotfix is available for download on
mysonicwall.com

CPE(s)


Workaround
None.

Fixed Software

Fixed Product    Fixed Version(s)   
SMA1000 Models - 6210, 7210, 8200v
        12.4.3-03526 (platform-hotfix) and higher versions.
        12.5.0-02952 (platform-hotfix) and higher versions.

Comments

IMPORTANT: Recommended Actions

All organizations with deployments of SMA1000 appliances
(whether virtual or physical) on affected versions must
perform the following:

    - Upgrade to the latest hotfix version – available via
https://www.mysonicwall.com
    - Contact SonicWall Technical Support for assistance
reviewing the system for indicators of compromise (IoCs).
    - If IOCs are detected on the system:
              - Re-image (hardware) or re-deploy (virtual) appliances.
              - Change all user & administrator passwords.
              - Reset TOTP tokens

Credit(s)

Internally discovered by William Perry and Adam Babis of
SonicWall.

Revision History

    Version

    1.0

    Date

    01-Sep-2026

    Description

    Initial Release.


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




