Back to all posts
Cybercriminals chain two SonicWall vulnerabilities to break into remote-access appliances

SonicWall disclosed two vulnerabilities in its SMA1000 remote-access appliances on 1 September, and cybercriminals are already exploiting both. CVE-2026-83548 scores a maximum 10.0 out of 10 (Critical) CVSS score and CVE-2026-83549 scores 7.8 (High). Chained together, they let a cybercriminal with no username or password run commands on the appliance.

What are these vulnerabilities?

An SMA1000 is the gateway staff log in to when they work remotely. It sits at the edge of the network and faces the internet by design.

CVE-2026-83548 is a Server-Side Request Forgery (SSRF), a vulnerability that tricks a server into making network requests on an outsider's behalf. SonicWall describes an unintended alternate access path in its Work Place portal, the page employees use to sign in. That path turns the appliance into an unintended forward proxy, relaying an outsider's requests to internal systems that should be out of reach. No login is needed.

CVE-2026-83549 sits in SonicWall's Appliance Management Console, the administrator control panel. It is a command injection vulnerability whereby the appliance treats part of a cybercriminal's input as an instruction to its operating system, not as plain data. On its own, it needs an administrator account, but the chain removes that obstacle. The first vulnerability carries the attacker to the management console, and the second one runs the commands.

Why this is dangerous

A cybercriminal that completes the chain controls the appliance. From there they can:

  • Read and alter traffic passing through the virtual private network (VPN).
  • Collect employee credentials as they arrive.
  • Use the device to reach deeper into the corporate network.

Remote-access gateways are a well-known ransomware entry point, because they hold access to everything behind them.

SonicWall confirmed cybercriminals exploited both vulnerabilities as zero-days, so attacks began before a patch existed. CISA added the pair to its KEV Catalog on 2 September and US federal agencies had until 5 September to fix them - far shorter than the usual three weeks. SonicWall has not named the group behind the attacks or released indicators of compromise. The Shadowserver Foundation counts more than 400 SMA1000 appliances reachable online.

Affected software

The vulnerabilities affect SMA1000 models 6210, 7210 and 8200v running platform-hotfix firmware 12.4.3-03453 or earlier, or 12.5.0-02835 or earlier. SonicWall states that SMA 100 series appliances and the SSL-VPN feature on SonicWall firewalls are not affected.

Mitigation and next steps

Upgrade to 12.4.3-03526 or 12.5.0-02952 or later. SonicWall offers no workaround, so patching is the only fix. Organizations that suspect a breach should re-image the appliance (or re-deploy it if virtual), then reset every user and administrator password along with all time-based one-time password (TOTP) tokens.

 


Need help? 

If you have any questions, don't hesitate to reach out.