CVE-2026-83548
sma8200v: Server-Side Request Forgery (SSRF) (CVE-2026-83548)
Affected
- sonicwall/sma8200v
lt *..12.4.3-03526 - sonicwall/sma8200v
between 12.5.0..12.5.0-02952 - sonicwall/sma6210_firmware
lt *..12.4.3-03526 - sonicwall/sma6210_firmware
between 12.5.0..12.5.0-02952 - sonicwall/sma7210_firmware
lt *..12.4.3-03526 - sonicwall/sma7210_firmware
between 12.5.0..12.5.0-02952
Response & Mitigation
Why act now?
Prioritisation rationale
This vulnerability carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — the maximum possible — because it is exploitable remotely with no authentication, no user interaction, and no complexity, and its scope extends beyond the appliance itself to internal systems. SMA1000 appliances sit at the network perimeter as remote-access gateways with privileged connectivity to internal services such as Active Directory and internal APIs, making SSRF pivoting from this position exceptionally dangerous. For NIS2-obligated organisations, particularly those in KRITIS sectors, this appliance is often part of critical remote-access infrastructure, and a successful exploit can serve as the initial foothold for full internal network compromise. Although CISA has not flagged known ransomware campaign use at time of KEV listing, KEV inclusion itself signals confirmed active exploitation — patch deployment must take precedence over all other vulnerability remediation work currently in queue.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch immediately: SonicWall has released a fix for the SMA1000 series. Firmware versions ≤ 12.4.3-03526 and 12.5.0-02952 are vulnerable across SMA 6210, 7210, and 8200v appliances — check the SonicWall PSIRT advisory for the exact target firmware version and deploy it now.
- Block external access to the Work Place interface: If patching within the hour is not feasible, place a firewall rule in front of the appliance restricting HTTPS (443/8443) access to the Work Place interface to known, trusted IP ranges only (VPN concentrators, management subnets). Drop all other inbound traffic.
- Isolate unpatched appliances: Any appliance that cannot be patched within 4 hours should be moved out of the DMZ into an isolated VLAN with no inbound internet exposure until the patch is applied.
- Preserve logs immediately: Export current SMA1000 access logs and syslog streams to immutable storage (SIEM with write-once policy, S3 Object Lock) before any remediation activity — these are your forensic baseline for determining whether exploitation has already occurred.
- Audit internal reachability from the appliance: SSRF allows the appliance to make server-side requests to internal targets. Identify which internal services (LDAP, AD, internal APIs, cloud metadata endpoints) are reachable from the appliance's IP and review their access logs for anomalous requests.
Runbook · Step 2
Mitigation layers
- Egress filtering on the appliance: Restrict outbound connections from the SMA1000 appliance IP to an explicit allowlist of required destinations. Block outbound connections to RFC-1918 ranges and cloud metadata endpoints (169.254.169.254) that are not operationally required — this directly limits SSRF pivot reach.
- WAF/reverse proxy with SSRF protection: Place a WAF in front of the Work Place interface and enable rules blocking SSRF-indicative payloads: requests containing
file://,dict://,gopher://,http://169.254., or internal IP ranges in URL parameters should be dropped before reaching the appliance. - Activate IPS signature for CVE-2026-83548: Check your NGFW/IPS vendor (SonicWall, Palo Alto, Fortinet, Snort community) for a published signature targeting this CVE and enable it on the perimeter device upstream of the SMA1000.
- Least-privilege for appliance service accounts: Reduce the permissions of any service account the SMA1000 uses to authenticate to internal services (LDAP/AD bind accounts, API tokens). Limit to read-only where possible — this constrains what an attacker can do after a successful SSRF pivot.
- Restrict admin interface to OOB management network: Ensure the SMA1000 administrative interface is only reachable via a dedicated out-of-band management VLAN, completely separated from the Work Place interface exposure.
Runbook · Step 3
Detection rules
- Web access log pattern (SMA1000 / upstream proxy): Hunt for unauthenticated requests to the Work Place interface containing SSRF-typical URL patterns —
@characters, double slashes, URL-encoded sequences (%40,%2F), or protocol schemes (gopher://,file://) — returning HTTP 200 or 302 without a valid session token. SPL:index=proxy sourcetype=access_combined uri_path="*%40*" OR uri_path="*gopher*" OR uri_path="*169.254*" status IN (200,302) - Network telemetry (Zeek/Suricata): Alert on outbound connections originating from the SMA1000 appliance IP to internal RFC-1918 destinations on non-standard ports (389, 636, 8080, 8443, 9200) that are not in the approved egress allowlist. Zeek filter:
id.orig_h == <SMA_IP> AND id.resp_h matches [10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16]. - SIEM correlation — unauthenticated requests with large backend responses: Flag HTTP requests to the Work Place interface lacking a valid session token that return HTTP 200 with a response body exceeding 5 KB — a potential indicator of SSRF data exfiltration from an internal service.
- EDR / Windows Event logs on downstream systems: Monitor internal servers (AD DCs, LDAP servers, internal APIs) for unexpected inbound connections from the SMA1000 appliance IP. Windows Event ID 4624 (Logon Type 3) originating from the appliance IP without a preceding legitimate authentication flow is a high-fidelity indicator.
- Sigma rule shape:
title: SMA1000 SSRF Unauthenticated Work Place Access | logsource: product: sonicwall_sma | detection: selection: http_path|contains: ['WorkPlace'] AND http_status: [200, 302] AND NOT session_token: '*' | condition: selection
Description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Affected operating systems
other
sonicwall / sma6210_firmware
other
sonicwall / sma7210_firmware
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
12.5.0 – 12.5.0-0295212.4.3-03526fixed from 12.4.3-03526Metrics
Show all metrics
Weakness classes (CWE)
CWE-918Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
cwe.mitre.org →CWE-441Class
Unintended Proxy or Intermediary ('Confused Deputy')
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-03 13:06 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- CVE CISA KEV Update2026-09-02 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-09-02
- Due Date: 2026-09-02
- Required Action: 2026-09-02
- Vulnerability Name: 2026-09-02
- CVE Modified2026-09-02 18:21 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548
- SSVC: {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- CVE Modified2026-09-02 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-09-01 22:17 UTC· PSIRT@sonicwall.com
- Description: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
- CWE: CWE-441
- CWE: CWE-918
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/83xxx/CVE-2026-83548.json">CVE-2026-83548</a>
Linked advisories
- csoonline2026-10-08 03:19 UTCSonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
- thehackernews2026-09-03 05:19 UTCCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
- csoonline2026-09-02 23:22 UTCSonicWall reports two major security holes under active exploit
- thehackernews2026-09-02 10:53 UTCAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- securityweek2026-09-02 05:04 UTCSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
- cert-fr2026-09-02 00:00 UTCMultiples vulnérabilités dans les produits SonicWall (02 septembre 2026)
- cert-fr2026-09-02 00:00 UTCMultiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)