important · Edge — Remote access
An exploited SMA1000 vulnerability pair may connect the prelogin portal to appliance command execution.
Affects
SonicWall SMA1000 6210, 7210, and 8200v secure remote-access and SSL-VPN appliances
SonicWall confirms active exploitation of both vulnerabilities.
Detail and 1 source
The reported composition joins pre-authentication SSRF or unintended forwarding to authenticated command injection, but the public record does not demonstrate the authentication transition.
Fixed firmware is available for both supported branches.
Chain to watch
Reach the Appliance WorkPlace interface before login→↓Use CVE-2026-83548 to issue an internal request→↓Cross the authentication boundary into the management console→↓Use CVE-2026-83549 to inject an operating-system command→↓The exact internal target and authentication transition between the two vulnerabilities remain unproven.
Unverified chainObtain an incident trace or reproduce the pair, recording the SSRF target, authentication transition, command sink and resulting process identity.