SonicWallCVE-2026-83548
SonicWall SMA1000: server-side request forgery
Critical10.0CVE-2026-83548 · Published Sep 1, 2026 · updated Sep 3, 2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SMA1000 Product | <= 12.4.3-03453 (platform-hotfix) and older versions | No fix yet |
| <= 12.5.0-02835 (platform-hotfix) and older versions | No fix yet |
Details and references
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 4 | SonicWall Network Security Manager (NSM): path traversal | Critical9.1 | No fix yet |
| Sep 4 | SonicWall Network Security Manager (NSM): missing authorization | Critical9.1 | No fix yet |
| Sep 4 | SonicWall Network Security Manager (NSM): command injection | Critical9.1 | No fix yet |
| Sep 1 | SonicWall SMA1000: command injection | High7.8 | No fix yet |
| Aug 25 | SonicWall NetExtender: path traversal | High8.8 | No fix yet |
| Aug 25 | SonicWall NetExtender: link following | High7.0 | No fix yet |