The gateway, which should separate the corporate network from external threats, itself has become the entry point. SonicWall confirmed the real-world attacks through two previously unknown vulnerabilities in SMA1000 devices for secure remote access. In the error bundle, allow an outsider to get to system commands without an account and execute the code on the device.
The first vulnerability of CVE-2026-83548 received a maximum of 10 points on the CVSS 3.1 scale. An error in the Appliance Work Place interface allows you to send requests on behalf of the gateway itself to authentication. This technique is called SSRF. As a result, the remote attacker can refer to the closed functions of the SMA1000 and perform operations that should not be available from the outside.
The second CVE-2026-83549 vulnerability with a score of 7.8 on the CVSS 3.1 scale is in the Appliance Management Console. Through the command injection, the administrator can transmit arbitrary OS commands to the system and achieve remote code execution. The error itself requires entry with administrator rights, but the first breach is able to open the way to it without a password.
SonicWall did not state directly that the intruders combined errors into one chain, but confirmed the operation of both. The National Cybersecurity Centre of the Health System of England indicates that the link can give the execution of the code without authentication. Who conducts attacks, what targets are chosen and what happens after penetration is not yet disclosed.
The problem affects the physical models of SMA 6210 and 7210, as well as the virtual SMA 8200v with releases 12.4.3-03453 and 12.5.0-02835 or earlier. The corrections are included in version 12.4.3-03526 and 12.5.0-02952. SMA1000 devices provide employees with access to the company’s applications and internal resources. SSL VPN on the SonyWall firewalls and the SMA 100 line are not subject to vulnerability.
Owners of SMA1000 recommend immediately installing a corrected version and contacting SonicWall to check for signs of compromise. If there are traces of hacking, the physical device needs to be re-written from a clean image, and the virtual to deploy again. After that, you should change the passwords of users and administrators, as well as reset the TOTP tokens.
The first vulnerability of CVE-2026-83548 received a maximum of 10 points on the CVSS 3.1 scale. An error in the Appliance Work Place interface allows you to send requests on behalf of the gateway itself to authentication. This technique is called SSRF. As a result, the remote attacker can refer to the closed functions of the SMA1000 and perform operations that should not be available from the outside.
The second CVE-2026-83549 vulnerability with a score of 7.8 on the CVSS 3.1 scale is in the Appliance Management Console. Through the command injection, the administrator can transmit arbitrary OS commands to the system and achieve remote code execution. The error itself requires entry with administrator rights, but the first breach is able to open the way to it without a password.
SonicWall did not state directly that the intruders combined errors into one chain, but confirmed the operation of both. The National Cybersecurity Centre of the Health System of England indicates that the link can give the execution of the code without authentication. Who conducts attacks, what targets are chosen and what happens after penetration is not yet disclosed.
The problem affects the physical models of SMA 6210 and 7210, as well as the virtual SMA 8200v with releases 12.4.3-03453 and 12.5.0-02835 or earlier. The corrections are included in version 12.4.3-03526 and 12.5.0-02952. SMA1000 devices provide employees with access to the company’s applications and internal resources. SSL VPN on the SonyWall firewalls and the SMA 100 line are not subject to vulnerability.
Owners of SMA1000 recommend immediately installing a corrected version and contacting SonicWall to check for signs of compromise. If there are traces of hacking, the physical device needs to be re-written from a clean image, and the virtual to deploy again. After that, you should change the passwords of users and administrators, as well as reset the TOTP tokens.