CVE-2026-83548

sma8200v: Server-Side Request Forgery (SSRF) (CVE-2026-83548)

Affected

  • sonicwall/sma8200v lt *..12.4.3-03526
  • sonicwall/sma8200v between 12.5.0..12.5.0-02952
  • sonicwall/sma6210_firmware lt *..12.4.3-03526
  • sonicwall/sma6210_firmware between 12.5.0..12.5.0-02952
  • sonicwall/sma7210_firmware lt *..12.4.3-03526
  • sonicwall/sma7210_firmware between 12.5.0..12.5.0-02952

Response & Mitigation

Why act now?

Prioritisation rationale

This vulnerability carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — the maximum possible — because it is exploitable remotely with no authentication, no user interaction, and no complexity, and its scope extends beyond the appliance itself to internal systems. SMA1000 appliances sit at the network perimeter as remote-access gateways with privileged connectivity to internal services such as Active Directory and internal APIs, making SSRF pivoting from this position exceptionally dangerous. For NIS2-obligated organisations, particularly those in KRITIS sectors, this appliance is often part of critical remote-access infrastructure, and a successful exploit can serve as the initial foothold for full internal network compromise. Although CISA has not flagged known ransomware campaign use at time of KEV listing, KEV inclusion itself signals confirmed active exploitation — patch deployment must take precedence over all other vulnerability remediation work currently in queue.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply the vendor patch immediately: SonicWall has released a fix for the SMA1000 series. Firmware versions ≤ 12.4.3-03526 and 12.5.0-02952 are vulnerable across SMA 6210, 7210, and 8200v appliances — check the SonicWall PSIRT advisory for the exact target firmware version and deploy it now.
  • Block external access to the Work Place interface: If patching within the hour is not feasible, place a firewall rule in front of the appliance restricting HTTPS (443/8443) access to the Work Place interface to known, trusted IP ranges only (VPN concentrators, management subnets). Drop all other inbound traffic.
  • Isolate unpatched appliances: Any appliance that cannot be patched within 4 hours should be moved out of the DMZ into an isolated VLAN with no inbound internet exposure until the patch is applied.
  • Preserve logs immediately: Export current SMA1000 access logs and syslog streams to immutable storage (SIEM with write-once policy, S3 Object Lock) before any remediation activity — these are your forensic baseline for determining whether exploitation has already occurred.
  • Audit internal reachability from the appliance: SSRF allows the appliance to make server-side requests to internal targets. Identify which internal services (LDAP, AD, internal APIs, cloud metadata endpoints) are reachable from the appliance's IP and review their access logs for anomalous requests.

Runbook · Step 2

Mitigation layers

  • Egress filtering on the appliance: Restrict outbound connections from the SMA1000 appliance IP to an explicit allowlist of required destinations. Block outbound connections to RFC-1918 ranges and cloud metadata endpoints (169.254.169.254) that are not operationally required — this directly limits SSRF pivot reach.
  • WAF/reverse proxy with SSRF protection: Place a WAF in front of the Work Place interface and enable rules blocking SSRF-indicative payloads: requests containing file://, dict://, gopher://, http://169.254., or internal IP ranges in URL parameters should be dropped before reaching the appliance.
  • Activate IPS signature for CVE-2026-83548: Check your NGFW/IPS vendor (SonicWall, Palo Alto, Fortinet, Snort community) for a published signature targeting this CVE and enable it on the perimeter device upstream of the SMA1000.
  • Least-privilege for appliance service accounts: Reduce the permissions of any service account the SMA1000 uses to authenticate to internal services (LDAP/AD bind accounts, API tokens). Limit to read-only where possible — this constrains what an attacker can do after a successful SSRF pivot.
  • Restrict admin interface to OOB management network: Ensure the SMA1000 administrative interface is only reachable via a dedicated out-of-band management VLAN, completely separated from the Work Place interface exposure.

Runbook · Step 3

Detection rules

  • Web access log pattern (SMA1000 / upstream proxy): Hunt for unauthenticated requests to the Work Place interface containing SSRF-typical URL patterns — @ characters, double slashes, URL-encoded sequences (%40, %2F), or protocol schemes (gopher://, file://) — returning HTTP 200 or 302 without a valid session token. SPL: index=proxy sourcetype=access_combined uri_path="*%40*" OR uri_path="*gopher*" OR uri_path="*169.254*" status IN (200,302)
  • Network telemetry (Zeek/Suricata): Alert on outbound connections originating from the SMA1000 appliance IP to internal RFC-1918 destinations on non-standard ports (389, 636, 8080, 8443, 9200) that are not in the approved egress allowlist. Zeek filter: id.orig_h == <SMA_IP> AND id.resp_h matches [10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16].
  • SIEM correlation — unauthenticated requests with large backend responses: Flag HTTP requests to the Work Place interface lacking a valid session token that return HTTP 200 with a response body exceeding 5 KB — a potential indicator of SSRF data exfiltration from an internal service.
  • EDR / Windows Event logs on downstream systems: Monitor internal servers (AD DCs, LDAP servers, internal APIs) for unexpected inbound connections from the SMA1000 appliance IP. Windows Event ID 4624 (Logon Type 3) originating from the appliance IP without a preceding legitimate authentication flow is a high-fidelity indicator.
  • Sigma rule shape: title: SMA1000 SSRF Unauthenticated Work Place Access | logsource: product: sonicwall_sma | detection: selection: http_path|contains: ['WorkPlace'] AND http_status: [200, 302] AND NOT session_token: '*' | condition: selection

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Affected operating systems

  • other

    sonicwall / sma6210_firmware

  • other

    sonicwall / sma7210_firmware

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

sonicwallsma8200v
12.5.0 – 12.5.0-0295212.4.3-03526fixed from 12.4.3-03526

Metrics

10.0
Source: cna-v3
95.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
8.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-09-01 22:17 UTC
CWE-918, CWE-441

Weakness classes (CWE)

  • CWE-918Base

    Server-Side Request Forgery (SSRF)

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

    cwe.mitre.org →
  • CWE-441Class

    Unintended Proxy or Intermediary ('Confused Deputy')

    The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-03 13:06 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  2. CVE CISA KEV Update2026-09-02 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-09-02
    • Due Date: 2026-09-02
    • Required Action: 2026-09-02
    • Vulnerability Name: 2026-09-02
  3. CVE Modified2026-09-02 18:21 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548
    • SSVC: {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  4. CVE Modified2026-09-02 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-83548","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  5. New CVE Received2026-09-01 22:17 UTC· PSIRT@sonicwall.com
    • Description: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
    • CWE: CWE-441
    • CWE: CWE-918
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/83xxx/CVE-2026-83548.json">CVE-2026-83548</a>

Linked advisories