Hackers Exploit Critical SonicWall SMA 1000 SSRF and RCE Flaws in Active Attacks

SonicWall has warned that threat actors are actively exploiting two vulnerabilities affecting SMA 1000 series secure access appliances, including a critical pre-authentication server-side request forgery (SSRF) flaw rated 10.0 out of 10 on the CVSS scale.

The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect SonicWall SMA 1000 models 6210, 7210, and 8200v running specified older platform-hotfix releases.

SonicWall’s Product Security Incident Response Team (PSIRT) said it investigated a case indicating active exploitation and urged customers to apply the available hotfix immediately.

Hackers Exploit Critical SonicWall SMA 1000 SSRF and RCE Flaws

CVE-2026-83548 is a pre-authentication SSRF vulnerability in the SMA 1000 Appliance Workplace interface. The flaw stems from an unintended alternate access path that can effectively operate as an unauthorized forward proxy.

A remote, unauthenticated attacker could exploit the issue to access sensitive functionality and conduct unauthorized operations through the affected appliance.

SonicWall assigned the flaw a CVSS v3 score of 10.0, reflecting network-based exploitation with no authentication or user interaction required.

The vulnerability is associated with CWE-918, Server-Side Request Forgery, and CWE-441, Unintended Proxy or Intermediary, also known as a confused-deputy weakness.

SSRF vulnerabilities are especially dangerous in internet-facing security appliances because they may allow attackers to make requests from a trusted internal position, bypassing network restrictions designed to protect management services.

The second issue, CVE-2026-83549, is a post-authentication remote code execution vulnerability in the SMA 1000 Appliance Management Console (AMC).

SonicWall said the flaw results from improper neutralization of special elements in OS commands, a common attack known as OS command injection.

Under specific conditions, an authenticated administrator could execute arbitrary operating-system commands on a vulnerable appliance.

Although the RCE flaw has a lower CVSS score of 7.8, it can become highly significant when combined with unauthorized access via the SSRF vulnerability.

Successful exploitation could allow attackers to establish persistence, alter appliance configurations, access sensitive data, or use the appliance as a pivot point into connected enterprise environments.

Affected and fixed versions

Affected SMA 1000 appliances include hardware and virtual deployments running:

  • Version 12.4.3-03453 platform-hotfix and earlier
  • Version 12.5.0-02835 platform-hotfix and earlier

SonicWall has released fixed platform-hotfix versions 12.4.3-03526 and 12.5.0-02952, as well as later releases, for affected SMA 1000 models.

The advisory does not apply to SSL-VPN services running on SonicWall firewalls or to the SMA 100 Series product line.

Mitigation

Organizations should identify exposed SMA 1000 appliances and upgrade them to the latest hotfix without delay. SonicWall said no workaround is available, making patching the primary mitigation.

Administrators should also contact SonicWall Technical Support to review appliances for indicators of compromise.

If evidence of intrusion is found, SonicWall recommends re-imaging hardware appliances or re-deploying virtual appliances, changing all user and administrator passwords, and resetting time-based one-time password (TOTP) tokens.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories