SonicWall SMA 1000 Series <= 12.4.3-03453 / 12.5.x <= 12.5.0-02835 Multiple Vulnerabilities (SNWLID-2026-0016)

critical Nessus Plugin ID 342663

Synopsis

The remote device is affected by multiple vulnerabilities.

Description

The remote host is a SonicWall SMA 1000 Series device that is affected by multiple vulnerabilities:

- A pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote, unauthenticated attacker could potentially exploit this to gain unauthorized access to sensitive functionality and perform unauthorized operations.
(CVE-2026-83548)

- A post-authentication improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the SMA1000 Appliance Management Console (AMC) which, in specific conditions, could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. (CVE-2026-83549)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to SonicWall SMA 1000 Series version 12.4.3-03526 or 12.5.0-02952 or later.

See Also

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

Plugin Details

Severity: Critical

ID: 342663

File Name: sonicwall_sma_SNWLID-2026-0016.nasl

Version: 1.2

Type: Remote

Family: CGI abuses

Published: 9/3/2026

Updated: 9/4/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.6

Percentile: 99.95

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-83548

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/o:sonicwall:firmware

Required KB Items: Settings/ParanoidReport, installed_sw/SonicWall Secure Mobile Access

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 9/1/2026

Reference Information

CVE: CVE-2026-83548, CVE-2026-83549

IAVA: 2026-A-0930