preloader

· · digital-security cve vulnerability vpn network kev vulnerability-management europe patch-management

Two SonicWall Bugs, Chained Together, Turn Your VPN Gateway Into an Open Door

Source: SecurityWeek

A remote-access gateway is only as trustworthy as its own front door. SonicWall just confirmed that two bugs in its SMA1000 series let an attacker walk through that door without a password.

One bug gets you in, the other gets you root

CVE-2026-83548, rated a maximum CVSS 10.0, is a pre-authentication server-side request forgery in the SMA1000’s Work Place portal, the interface remote users hit first when connecting. On its own, it lets an unauthenticated attacker make the appliance issue requests on their behalf.

CVE-2026-83549, rated 7.8, is an OS command injection in the Appliance Management Console. Normally that would require admin credentials to reach, which is why it is rated lower on its own. Chained with the SSRF, though, an attacker never needs those credentials in the first place: the first bug gets them to the console, the second gets them a shell.

The affected models are the SMA1000 series 6210, 7210 and 8200v, the appliances organisations deploy specifically to give staff secure remote access to internal networks. SonicWall shipped hotfixes 12.4.3-03526 and 12.5.0-02952 on September 1, the same day it disclosed both bugs.

CISA gave this a Friday deadline

CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 2, confirming active exploitation, and set a remediation deadline of September 5 for US federal agencies. A same-week KEV deadline is CISA’s way of saying attackers are not waiting, and a gateway product built to sit on the public internet is exactly the kind of asset that gets swept up in opportunistic scanning within days of a KEV listing, regardless of which country runs it.

What to do now

If your organisation runs an SMA1000 appliance, confirm you are on 12.4.3-03526, 12.5.0-02952 or later today, and check your logs for Work Place portal requests that do not match normal remote-access patterns. A VPN gateway compromised at the appliance level bypasses every access control behind it, which makes this worth treating as urgent rather than routine patching.

If you would like a second set of eyes on your remote-access infrastructure, contact Excello Digital. We help European organisations audit exactly the kind of internet-facing gateway that this bug targets, before an attacker finds it first.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!