CRITICAL🚩 CISA KEV⚡ EXPLOIT🇬🇧 English

CVE-2026-83548

CVSS 10.0pub. 2026-09-01upd. 2026-09-03

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Sonicwall Sma6210

    HW
    Sonicwall
    wszystkie wersje
  • Sonicwall Sma6210 Firmware

    OS
    Sonicwall
    < 12.4.3-0352612.5.0 – 12.5.0-02952 (bez)
  • Sonicwall Sma7210

    HW
    Sonicwall
    wszystkie wersje
  • Sonicwall Sma7210 Firmware

    OS
    Sonicwall
    < 12.4.3-0352612.5.0 – 12.5.0-02952 (bez)
  • Sonicwall Sma8200v

    APP
    Sonicwall
    12.5.0 – 12.5.0-02952 (bez)< 12.4.3-03526

CISA KEV — szczegółyi

Dostawcai
SonicWall
Produkti
SMA1000 Appliances
Data dodania do KEVi
2 września 2026
Termin remediation (USA)i
5 września 2026(po terminie)
Wymagana akcja (CISA)i

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

oryginał EN
Opis CISAi

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

oryginał EN
🔴
NATYCHMIASTOWE DZIAŁANIE
Aktywnie wykorzystywane w atakach (CISA KEV). Załataj jak najszybciej.
CISA DEADLINE: 5 września 2026
Tagi
SSRFAuth Bypass
CWE
Referencje

Powiązane podatności

CVE-2026-15409CRITICAL10.0⚠ KEVPL ✓ten sam produkt

SSRF w SonicWall SMA1000 — nieuwierzytelniony dostęp do wewnętrznych zasobów

CVE-2025-23006CRITICAL9.8⚠ KEVPL ✓ten sam produkt

SonicWall SMA1000 — pre-auth deserialization umożliwiający RCE

CVE-2026-83549HIGH7.8⚠ KEVten sam produkt

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...

CVE-2026-15410HIGH7.2⚠ KEVPL ✓ten sam produkt

SonicWall SMA1000 AMC – Code Injection umożliwiający wykonanie poleceń OS

CVE-2026-4112HIGH7.2ten sam produkt

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 seri...