SonicWallCVE-2026-83549
SonicWall SMA1000: command injection
High7.8CVE-2026-83549 · Published Sep 1, 2026 · updated Sep 21, 2026
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SMA1000 Product | <= 12.4.3-03453 (platform-hotfix) and older versions | No fix yet |
| <= 12.5.0-02835 (platform-hotfix) and older versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-78
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 4 | SonicWall Network Security Manager (NSM): path traversal | Critical9.1 | No fix yet |
| Sep 4 | SonicWall Network Security Manager (NSM): missing authorization | Critical9.1 | No fix yet |
| Sep 4 | SonicWall Network Security Manager (NSM): command injection | Critical9.1 | No fix yet |
| Sep 1 | SonicWall SMA1000: server-side request forgery | Critical10.0 | No fix yet |
| Aug 25 | SonicWall NetExtender: path traversal | High8.8 | No fix yet |
| Aug 25 | SonicWall NetExtender: link following | High7.0 | No fix yet |