SonicWall SMA 1000 devices can be hacked remotely
Attackers are actively breaking into SonicWall SMA 1000 remote access gateways without needing a password. Two flaws let them reach hidden admin functions and then run their own commands on the device.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Affects
- SonicWall SMA 1000
- Exploited
- Not confirmedNo confirmation recorded
How it works
- One flaw lets an outsider trick the device's user-facing login portal into making requests to internal systems it should never reach, bypassing the need to log in at all.
- A second flaw then lets a logged-in attacker sneak extra operating system commands into a request to the admin console, and SonicWall says the two can be used together to take over the...
What to do
Check your SMA 1000 appliance's current firmware version against SonicWall's advisory for CVE-2026-83548 and CVE-2026-83549 in the MySonicWall portal or admin console, since SonicWall has confirmed active exploitation.
Apply the SonicWall-issued firmware patch for both CVEs immediately through MySonicWall, and review SMA 1000 logs for signs of the unauthorized access SonicWall's PSIRT says it already found in at least one case.
Technical details
CVE-2026-83548 is a pre-authentication SSRF (outdated CVSS versions) in the SMA 1000 Appliance Work Place interface caused by an unintended alternate access path, letting a remote unauthenticated attacker reach sensitive internal functionality. CVE-2026-83549 is a post-authentication OS command injection flaw (CVSS 7.8) in the Appliance Management Console that lets an authenticated attacker execute arbitrary OS commands under specific conditions. Rapid7 notes the two can be chained into unauthenticated remote code execution, though no public PoC or IOCs were available at publication. This follows two earlier SMA 1000 zero-days exploited earlier in the summer.