Skip to finding
important · Edge — Remote access

An exploited SMA1000 vulnerability pair may connect the prelogin portal to appliance command execution.

Affects

SonicWall SMA1000 6210, 7210, and 8200v secure remote-access and SSL-VPN appliances

SonicWall confirms active exploitation of both vulnerabilities.

Detail and 1 source

The reported composition joins pre-authentication SSRF or unintended forwarding to authenticated command injection, but the public record does not demonstrate the authentication transition.

Fixed firmware is available for both supported branches.

Chain to watch
Reach the Appliance WorkPlace interface before login→↓Use CVE-2026-83548 to issue an internal request→↓Cross the authentication boundary into the management console→↓Use CVE-2026-83549 to inject an operating-system command→↓The exact internal target and authentication transition between the two vulnerabilities remain unproven.
Unverified chainObtain an incident trace or reproduce the pair, recording the SSRF target, authentication transition, command sink and resulting process identity.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026