AIO APEX

SonicWall SMA 1000 zero-days chained for unauthenticated remote code execution

The Hacker News
Share:
SonicWall SMA 1000 zero-days chained for unauthenticated remote code execution

SonicWall has disclosed two zero-day vulnerabilities in its SMA 1000 series appliances that attackers are actively chaining together to achieve unauthenticated remote code execution — meaning a hacker can fully compromise the device without ever logging in. The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) bug in the appliance's Work Place interface and carries the maximum possible CVSS score of 10.0. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the Appliance Management Console, rated 7.8.

On their own, each flaw is serious but contained. Together, they're a full compromise path: an attacker uses the unauthenticated SSRF bug to reach the management console internally, then pivots through the command-injection flaw to execute arbitrary operating system commands — all without a valid credential. SonicWall said it “investigated a case indicating the active exploitation of the vulnerabilities,” confirming attackers are already using the chain in the wild rather than this being a theoretical risk flagged only by researchers.

The vulnerabilities affect SMA 1000 series models 6210, 7210, and 8200v running platform-hotfix versions 12.4.3-03453 or 12.5.0-02835 and earlier. SonicWall has shipped fixed builds — 12.4.3-03526 and 12.5.0-02952 — and is urging customers to upgrade immediately rather than wait for a scheduled maintenance window. The bugs were found internally by SonicWall researchers William Perry and Adam Babis.

SMA appliances sit at the network perimeter by design, typically handling secure remote access and VPN connections for an organization's workforce. That makes them a high-value target: a compromised SMA device can give an attacker a foothold deep inside a corporate network, bypassing the layers of internal security that would normally stand between an external attacker and sensitive systems. This is also not SonicWall's first SMA incident this year — the disclosure comes roughly a month after the company patched a separate pair of SMA flaws, CVE-2026-15409 and CVE-2026-15410, which the threat actor tracked as UTA0533 exploited to deploy custom malware known as KNUCKLEBALL.

Beyond patching, SonicWall is recommending that administrators actively hunt for signs of prior compromise rather than assume a clean bill of health once the update is applied. Its guidance for organizations that find indicators of compromise is unusually blunt: re-image or fully re-deploy the affected appliance, reset every user and administrator password tied to it, and reset all time-based one-time password (TOTP) seeds. That level of remediation reflects how much trust a compromised perimeter appliance can quietly accumulate before anyone notices — session tokens, cached credentials, and TOTP secrets are all things a re-image alone won't necessarily flush out if an attacker had console access.

Organizations running any of the affected SMA 1000 models should treat this as an emergency patch, not a routine one: apply the hotfix immediately and review logs for the exploitation pattern SonicWall has outlined, even if the appliance appears to be functioning normally.

As first reported by The Hacker News.

Originally reported by The Hacker News. Read the original article for additional details.

View original source
Share: