SonicWall has warned customers that threat actors are chaining two SMA1000 zero-day vulnerabilities in remote code execution attacks.
The first flaw, CVE-2026-83548, is a maximum-severity command injection vulnerability in the SMA1000 Appliance WorkPlace interface. It stems from a server-side request forgery (SSRF) weakness. The second, CVE-2026-83549, is a command injection vulnerability in the SMA1000 Appliance Management Console. Attackers with admin privileges can exploit it to execute arbitrary OS commands on vulnerable devices.
SonicWall PSIRT investigated a case indicating active exploitation and urged customers to upgrade their virtual or physical SMA1000 appliances to the latest hotfix version. The company also advised administrators to re-image appliances, change user and administrator passwords, and reset TOTP tokens if indicators of compromise (IOCs) are detected.
The flaws affect the SMA1000 6210, 7210, and 8200v models. They do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.
Shadowserver currently tracks more than 400 SMA1000 appliances exposed online, although some may already have been patched. SonicWall has not shared details about the ongoing attacks or a list of IOCs identified during its investigation.
Comments
0No comments yet. Be the first to comment.