SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

A New Wave of SonicWall SMA 1000 Zero-Days Enables Unauthenticated RCE Attacks

The cybersecurity community is bracing itself for yet another wave of attacks on SonicWall’s SMA 1000 perimeter devices, this time exploiting two zero-day vulnerabilities that enable unauthenticated remote code execution (RCE). The latest exploits follow a summer of similar attacks on other SMA 1000 zero-days, highlighting the urgent need for affected customers to patch their systems immediately.

The two newly disclosed flaws are a pre-authentication server-side request forgery (SSRF) vulnerability, designated as CVE-2026-83548 with a maximum CVSS 3.0 score of 10, and a post-authentication OS Command Injection vulnerability, identified as CVE-2026-83549 with a score of 7.8. The first vulnerability is present in the SMA 1000 Appliance Work Place interface (the user-facing portal), while the latter resides in the SMA 1000 Appliance Management Console (AMC) – the administrator’s portal for remote access gateways.

According to SonicWall, the SSRF bug is caused by an unintended alternate access path. A remote, unauthenticated attacker could exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. The OS Command Injection flaw, on the other hand, allows an authenticated remote attacker to execute arbitrary OS commands leading to RCE.

While no public proof-of-concept exploit or indicators of compromise (IOCs) have been identified at the time of writing, SonicWall’s investigation into a case indicating active exploitation of these vulnerabilities suggests that attackers are indeed exploiting them in the wild. Moreover, Rapid7 notes that the role of SMA 1000 devices as network edge devices makes successful exploitation particularly concerning, as it could result in significant control over affected systems.

The affected SonicWall SMA 1000 models – versions 6210, 7210, and 8200v – run on firmware 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. SonicWall urges customers to upgrade to at least version 12.4.3-03526/12.5.0-02952 (platform-hotfix) or higher to mitigate the risks.

The ongoing attacks on SMA 1000 devices, coupled with the ease of chaining these vulnerabilities for RCE, serve as a stark reminder that remote access gateways like SonicWall’s SMA 1000 are attractive targets for attackers due to their frequent exposure directly to the internet. Affected customers should take immediate action by patching their systems and reviewing for any indicators of compromise.

In light of this latest development, we recommend that all affected customers prioritize patching their systems as soon as possible, change all user and administrator passwords, reset TOTP tokens, and re-image or re-deploy compromised appliances if necessary.


Source: Dark Reading — 2026-09-02