Threat Insight
SonicWall Vulnerabilities Exploited in the Wild
Two recently disclosed vulnerabilities in SonicWall[1] appliances are actively being exploited in the wild.
CVE-2026-83548: A critical, unauthenticated server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. It allows attackers to reach sensitive internal functionality through an unintended access path.
CVE-2026-83549: A high-severity OS command injection vulnerability in the Appliance Management Console (AMC). It can allow arbitrary operating-system command execution.
These two vulnerabilities can be chained together to achieve unauthenticated remote code execution, allowing attackers to access sensitive functionality and perform unauthorized operations.
CVE
CVE-2026-83548
CVE-2026-83549
Affected Products
SMA1000 Models – 6210, 7210, 8200v running the following versions:
- 12.4.3-03453 platform-hotfix and earlier
- 12.5.0-02835 platform-hotfix and earlier
Exploitation
Both CVE-2026-83548 and CVE-2026-83549 have recently been added to the CISA database of known exploited vulnerabilities[2].
Recommended Actions
Truesec recommends upgrading affected SonicWall appliances to the patched versions:
- 12.4.3-03526 platform-hotfix, for systems on the 12.4.3 branch
- 12.5.0-02952 platform-hotfix, for systems on the 12.5.0 branch
If evidence of compromise is identified we recommend:
- Re-imaging affected hardware appliances or re-deploying affected virtual appliances.
- Changing all user and administrator passwords.
- Resetting Time-based One-Time Password (TOTP) tokens.
Detection
Review SMA1000 syslogs for:
- POST requests to /workplace/ containing URL-encoded internal IP addresses, loopback addresses, or management hostnames in query parameters or request bodies.
- AMC access originating from the appliance’s own workplace process instead of approved administrator workstations or management networks.
Investigate requests involving:
- /workplace/
- /appliance/
- 127.0.0.1
References
[1] https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild
[2] https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com