> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2026-83549 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- URL: https://f4n6.co.uk/security-feed/cve-2026-83549-sonicwall-sma1000-appliances-sonicwall-sma1000-appliances-os-command-injection-vulnerability/
- Published: 2026-09-02T20:43:40.000Z
- Updated: 2026-09-02T20:43:40.000Z
- Author: Jeff Davies
- Tags: #security-feed, CVE-2026-83549

## 1\. Executive summary

SonicWall has confirmed active in-the-wild exploitation of two chained zero-day vulnerabilities in its SMA1000 secure remote access appliances: CVE-2026-83548, a pre-authentication SSRF in the Appliance Work Place interface (CVSS 10.0, per vendor), and CVE-2026-83549, an OS command injection in the Appliance Management Console (CVSS 7.8 HIGH, CWE-78, in CISA KEV since 2026-09-02, EPSS 1%). Chained, the pair yields unauthenticated remote code execution on an internet-facing edge device — a direct route into corporate networks for EMEA financial services clients running SMA 6210, 7210 or 8200v models. CISA's KEV remediation due date is 2026-09-05, and there are no vendor workarounds; SonicWall's platform hotfixes (12.4.3-03526 / 12.5.0-02952) are the only fix path. No IOCs, PoC or attribution have been published, so patching alone cannot establish whether an appliance is already compromised — assume compromise investigation is required for any vulnerable, internet-exposed unit.

## 2\. Regulatory framing

| Article                                                                         | Trigger (the fact in this item)                                                                                                                                                                                                           | Practical impact                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | Confirmed zero-day exploitation of an internet-facing remote-access gateway, with no IOCs available to rule out prior compromise — a network-edge device that brokers access to internal applications cannot be presumed clean post-patch | Clients must be ready to classify this as a potential major ICT-related incident under their Art. 18 process and report within statutory windows if forensic review finds evidence of compromise, not merely record it as a patched vulnerability |
| DORA Art. 28: ICT third-party risk — general principles                         | The affected appliance is a vendor-supplied edge security product whose vendor (SonicWall) has now shipped two similar exploited zero-day pairs on the same product line within \~2 months (July 2026 pair, this pair)                    | Clients should reassess the risk posed by this specific vendor/product in their ICT third-party register and contractual posture (Art. 30 provisions), rather than treat this as routine patching                                                 |

No NIS2 or UK NIS article is directly engaged beyond generic incident/patching duties; the item's distinctive facts (edge-gateway compromise potential, repeat vendor zero-days) map to the DORA rows above.

## 3\. Technical analysis & attack chain

**Vulnerability mechanism.** CVE-2026-83549 is an OS command injection (CWE-78, CVSS 7.8 HIGH) in the SMA1000 Appliance Management Console (AMC). Standalone exploitation requires an authenticated administrator session and specific system conditions; the injected commands execute as arbitrary OS commands on the appliance, i.e. remote code execution. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface, which SonicWall attributes to an unintended alternative access path; it allows a remote unauthenticated attacker to reach sensitive functionality and perform unauthorised operations. The chain: the SSRF provides the unauthenticated route to the functionality that CVE-2026-83549 then injects into, converting a post-auth admin-only command injection into unauthenticated RCE.

### Confirmed attack chain (vendor-confirmed exploitation; steps inferred from the published mechanism, not from observed telemetry)

1. Attacker reaches an internet-exposed SMA1000 Work Place interface (normal deployment exposes this).
2. CVE-2026-83548 (SSRF) is abused to access sensitive internal functionality via the unintended alternate access path, without authentication.
3. The attacker uses that access to drive the AMC functionality vulnerable to CVE-2026-83549, injecting OS commands that would normally require an authenticated administrator.
4. Arbitrary OS command execution on the appliance yields control of the remote-access gateway and a foothold into the internal network it fronts.

### Affected and fixed versions (per SonicWall via Rapid7)

| Model                 | Vulnerable                               | Fixed                                   |
| --------------------- | ---------------------------------------- | --------------------------------------- |
| SMA 6210, 7210, 8200v | 12.4.3-03453 platform-hotfix and earlier | 12.4.3-03526 platform-hotfix and higher |
| SMA 6210, 7210, 8200v | 12.5.0-02835 platform-hotfix and earlier | 12.5.0-02952 platform-hotfix and higher |

**Caveats and confidence.** SonicWall has confirmed active exploitation of both CVEs, but no IOCs, no public PoC, and no attribution have been released (Rapid7, The Register). The exploitation claim is vendor-confirmed and corroborated by CISA KEV listing; the step-by-step chain above is a mechanism reconstruction, not observed attacker behaviour. The Register notes a near-identical July 2026 pair (pre-auth SSRF in Work Place + post-auth OS command injection in AMC, CVE-2026-15409/15410) on the same product line, with CVE-2026-15409 later marked as used in ransomware campaigns — that is historical context for this product line, not evidence of ransomware in the current campaign. No ransomware use is recorded for either current CVE ("Known ransomware campaign use: Unknown"). NHS England's National CSOC assesses future exploitation as "almost certain" (single-sourced to NHS England via The Register).

## 4\. Mitigation & containment

### P1 — within 24 hours

1. **Inventory and patch.** Locate all SMA1000 appliances (models 6210, 7210, 8200v) and upgrade to 12.4.3-03526 platform-hotfix (12.4.3 branch) or 12.5.0-02952 platform-hotfix (12.5.0 branch). CISA KEV due date is 2026-09-05 — three days from issue. There are no workarounds (The Register).
2. **Reduce exposure.** Where patching cannot be completed immediately, remove or restrict internet exposure of the Work Place interface and AMC (management plane should never be internet-facing); if the appliance cannot be patched or isolated, CISA's KEV guidance is to discontinue use of the product.
3. **Assume-compromise triage.** Because exploitation predates disclosure, do not treat patching as evidence of a clean appliance. Contact SonicWall Technical Support for IOC review of any vulnerable unit (vendor-recommended path). Rapid7 Exposure Command / InsightVM / Nexpose checks for both CVEs were scheduled for the 3 September content release.

### P2 — within 72 hours

1. **If compromise is evidenced**, follow SonicWall's recovery guidance: re-image affected hardware appliances or re-deploy affected virtual appliances; change all user and administrator passwords; reset all TOTP tokens. Do not attempt in-place cleanup on an edge device with confirmed command execution.
2. **Review authentication and session logs** on the appliance and downstream systems for the pre-disclosure window, prioritising appliances that were internet-exposed on vulnerable firmware.

### P3 — within 7 days

1. **Vendor risk review.** Given the second exploited zero-day pair on this product line in two months, review the SonicWall SMA1000 entry in the third-party register (DORA Art. 28) and confirm contractual security-update and incident-notification provisions (Art. 30).
2. **Confirm patch coverage** across all branches and re-verify no appliance has drifted back to vulnerable hotfix levels; add the two fixed hotfix versions to configuration baselines.

## 5\. Indicators of compromise

No indicators of compromise available in the source material. Rapid7 explicitly states that no IOCs were identified at time of publication, and SonicWall directs customers to its Technical Support for compromise review rather than publishing indicators. No behavioural indicators are described in the sources beyond the vulnerability mechanism itself.

## 6\. Detection

Insufficient indicators to author detection rules. The sources contain no artefacts of the exploitation itself — no request patterns, URIs, payloads, log signatures, file names or command strings. Detection content should be sourced from SonicWall Technical Support (vendor IOC review) and the Rapid7 content release of 3 September 2026 once available; do not deploy rules built from CVE identifiers or product names, as these detect reporting, not exploitation.

## CVE assessment

1 referenced CVE — **1 actively exploited (CISA KEV)**

| CVE                                                                              | CVSS     | Exploited        | EPSS | Summary                                                                                                                          |
| -------------------------------------------------------------------------------- | -------- | ---------------- | ---- | -------------------------------------------------------------------------------------------------------------------------------- |
| [CVE-2026-83549](https://nvd.nist.gov/vuln/detail/CVE-2026-83549?ref=f4n6.co.uk) | 7.8 High | ⚠ KEV 2026-09-02 | 1%   | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability ha… |

## 7\. Sources

- NVD — CVE-2026-83549 — SonicWall SMA1000 Appliances OS Command Injection Vulnerability — https://nvd.nist.gov/vuln/detail/CVE-2026-83549 — 2026-09-01
- Rapid7 — Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild — https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild — 2026-09-02
- NVD — CVE-2026-83548 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability — https://nvd.nist.gov/vuln/detail/CVE-2026-83548 — 2026-09-01
- The Register — SonicWall's SMA1000 boxes under active attack again — https://www.theregister.com/security/2026/09/02/sonicwalls-sma1000-boxes-under-active-attack-again/5293969 — 2026-09-02
- Help Net Security — SonicWall SMA 1000 appliances under attack via zero-day flaws — https://www.helpnetsecurity.com/2026/09/02/sonicwall-sma-1000-cve-2026-83548-cve-2026-83549-zero-day-attacks/ — 2026-09-02
- SecurityWeek — SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks — https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/ — 2026-09-02
- NVD — CVE-2026-15410 — SonicWall SMA1000 Appliances Code Injection Vulnerability (context) — https://nvd.nist.gov/vuln/detail/CVE-2026-15410 — 2026-07

## 8\. Adverse Trace position

CVE-2026-83549 is a HIGH (CVSS 7.8) OS command injection, in CISA KEV with a 2026-09-05 remediation deadline, and is being actively exploited in the wild chained with a 10.0-scored pre-auth SSRF to give unauthenticated RCE on an internet-facing access gateway — for any EMEA financial services client operating SMA1000 appliances this is an emergency-patch situation with a mandatory assume-compromise review, because exploitation predates disclosure and no IOCs exist to rule out prior access. The absence of IOCs, PoC and attribution means detection coverage currently depends entirely on vendor support engagement; treat any claim of compromise or non-compromise on these appliances as single-sourced until SonicWall or CISA publishes indicators. Adverse Trace will monitor for SonicWall IOC publication, CISA KEV updates, and the Rapid7 detection content due 3 September, and will reissue this advisory if indicators, attribution or ransomware linkage are confirmed.

---

[Read the original source →](https://nvd.nist.gov/vuln/detail/CVE-2026-83549?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*