SonicWall has issued an urgent call for its users to update their SMA1000 series secure remote access and SSL-VPN devices due to the discovery of two critical zero-day vulnerabilities. These vulnerabilities have been actively exploited, prompting immediate action from the company.
Details of the Discovered Vulnerabilities
The advisory, released by SonicWall on Tuesday, highlights that the vulnerabilities were identified through internal investigations. The first vulnerability, identified as CVE-2026-83548, has a CVSS score of 10, indicating its critical nature. This flaw is a pre-authentication server-side request forgery (SSRF) issue found in the Appliance Work Place interface, allowing attackers to remotely execute unauthorized operations without needing authentication.
The second vulnerability, CVE-2026-83549, holds a CVSS score of 7.8. It involves an OS command injection issue within the Appliance Management Console (AMC). If exploited, it could enable an authenticated attacker to execute arbitrary operating system commands, potentially leading to remote code execution.
Exploitation and Affected Models
SonicWall has observed exploitation of both vulnerabilities, suggesting they are being used together in attacks. The models impacted include SMA1000 series versions 6210, 7210, and 8200v. However, SonicWall’s SSL-VPN on firewalls and the SMA100 series products remain unaffected by these vulnerabilities.
To address these security issues, SonicWall has released hotfixes, specifically versions 12.4.3-03526, 12.5.0-02952, and higher, which users are urged to implement immediately to secure their systems.
Security Implications and Recommendations
While specific details about the attacks exploiting these vulnerabilities have not been made public, SonicWall’s advisory has emphasized the critical nature of patching these flaws to prevent potential breaches. Notably, the Cybersecurity and Infrastructure Security Agency (CISA) has not yet added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, although SonicWall products are frequently targeted in such attacks.
Given the history of SonicWall vulnerabilities being exploited, sometimes for extended periods before patching, the importance of timely updates cannot be overstated. Organizations using affected models should prioritize deployment of the recommended patches to safeguard their networks against potential exploitation.
With cybersecurity threats constantly evolving, SonicWall’s proactive measures in alerting users underscore the need for vigilance and prompt action in addressing security vulnerabilities.
