CVE-2026-83549

9.5 CISA KEV

SonicWall · SMA1000 Appliances

A post-authentication OS command injection vulnerability exists in the SonicWall SMA1000 Appliance Management Console, allowing an authenticated administrator to execute arbitrary OS commands.

Executive summary

This critical vulnerability in SonicWall SMA1000 appliances is currently being actively exploited in the wild, posing an immediate risk of full system compromise.

Vulnerability

The flaw is an improper neutralization of special elements used in an OS command (CWE-78) within the Appliance Management Console. It requires an attacker to have authenticated access as an administrator to trigger the injection, which facilitates remote code execution.

Business impact

The ability to execute arbitrary OS commands on a security appliance represents a total loss of confidentiality, integrity, and availability. With a CVSS score of 9.5, this vulnerability allows an attacker who has compromised administrative credentials to take full control of the device, potentially leading to lateral movement, data exfiltration, and persistent unauthorized access to the internal network.

Remediation

Immediate Action: Update the affected SMA1000 appliances to the latest patched firmware versions as specified in the official SonicWall PSIRT advisory immediately.

Proactive Monitoring: Review system logs for unusual process execution, unauthorized modifications to the Appliance Management Console, or unexpected outbound connections originating from the management interface.

Compensating Controls: Restrict administrative access to the Management Console to trusted IP addresses only and ensure that multi-factor authentication is strictly enforced for all administrator accounts to prevent unauthorized access.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the confirmed active exploitation and the critical nature of this vulnerability, immediate patching is required to protect your infrastructure. Organizations should verify their current firmware version against the affected list provided by SonicWall and apply the necessary hotfixes or updates without delay to prevent potential system compromise.

More SonicWall CVEs

Sources