Threat Insight

SonicWall Vulnerabilities Exploited in the Wild

Two recently disclosed vulnerabilities in SonicWall[1] appliances are actively being exploited in the wild.

  • Insight

CVE-2026-83548: A critical, unauthenticated server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. It allows attackers to reach sensitive internal functionality through an unintended access path.

CVE-2026-83549: A high-severity OS command injection vulnerability in the Appliance Management Console (AMC). It can allow arbitrary operating-system command execution.

These two vulnerabilities can be chained together to achieve unauthenticated remote code execution, allowing attackers to access sensitive functionality and perform unauthorized operations.

CVE

CVE-2026-83548
CVE-2026-83549

Affected Products

SMA1000 Models – 6210, 7210, 8200v running the following versions:

  • 12.4.3-03453 platform-hotfix and earlier
  • 12.5.0-02835 platform-hotfix and earlier
    Exploitation

Both CVE-2026-83548 and CVE-2026-83549 have recently been added to the CISA database of known exploited vulnerabilities[2].

Recommended Actions

Truesec recommends upgrading affected SonicWall appliances to the patched versions:

  • 12.4.3-03526 platform-hotfix, for systems on the 12.4.3 branch
  • 12.5.0-02952 platform-hotfix, for systems on the 12.5.0 branch

If evidence of compromise is identified we recommend:

  • Re-imaging affected hardware appliances or re-deploying affected virtual appliances.
  • Changing all user and administrator passwords.
  • Resetting Time-based One-Time Password (TOTP) tokens.
    Detection

Review SMA1000 syslogs for:

  • POST requests to /workplace/ containing URL-encoded internal IP addresses, loopback addresses, or management hostnames in query parameters or request bodies.
  • AMC access originating from the appliance’s own workplace process instead of approved administrator workstations or management networks.

Investigate requests involving:

  • /workplace/
  • /appliance/
  • 127.0.0.1
    References

[1] https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild
[2] https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights