Skip to finding
important · Firmware — SonicWall

A working exploit now turns the SMA1000 WorkPlace proxy into root command execution.

Affects

SonicWall SMA 1000 Series 6210, 7210 and virtual 8200v secure remote-access appliances.

The chain uses the unauthenticated forward proxy to reach a protected AMC command-injection path and run commands as root.

Detail and 2 sources

SonicWall also reports active exploitation of the two flaws.

Fixed builds are available, but pre-fix appliance images remain accepted.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026