Skip to content
SonicWallCVE-2026-83549

SonicWall SMA1000: command injection

High7.8CVE-2026-83549 · Published Sep 1, 2026 · updated Sep 21, 2026

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

SonicWall advisory

Affected versions

PackageAffectedFixed in
SMA1000
Product
<= 12.4.3-03453 (platform-hotfix) and older versionsNo fix yet
<= 12.5.0-02835 (platform-hotfix) and older versionsNo fix yet
Details and references

More SonicWall advisories

All SonicWall
Advisory
SonicWall Network Security Manager (NSM): path traversal
Critical9.1Sep 4
SonicWall Network Security Manager (NSM): missing authorization
Critical9.1Sep 4
SonicWall Network Security Manager (NSM): command injection
Critical9.1Sep 4
SonicWall SMA1000: server-side request forgery
Critical10.0Sep 1
SonicWall NetExtender: path traversal
High8.8Aug 25
SonicWall NetExtender: link following
High7.0Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.