CVE-2026-83549
sma8200v: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CVE-2026-83549)
Affected
- sonicwall/sma8200v
lt *..12.4.3-03526 - sonicwall/sma8200v
between 12.5.0..12.5.0-02952 - sonicwall/sma6210_firmware
lt *..12.4.3-03526 - sonicwall/sma6210_firmware
between 12.5.0..12.5.0-02952 - sonicwall/sma7210_firmware
lt *..12.4.3-03526 - sonicwall/sma7210_firmware
between 12.5.0..12.5.0-02952
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-83549 carries a CVSS 7.8 score (AV:L/AC:L/PR:L/UI:N); while the local attack vector (AV:L) might suggest limited remote exploitability, the vulnerability resides in the network-accessible AMC web interface, meaning any authenticated remote administrator can trigger it without physical access. CISA's KEV listing confirms active exploitation in the wild. SMA1000 appliances typically serve as VPN gateways and remote-access concentrators in enterprise and critical-infrastructure environments, so a successful RCE grants an attacker full control of the gateway and a pivot point into internal network segments — the business impact is critical regardless of the CVSS base score. No known-ransomware-campaign flag is set at this time, but gateway compromise is a well-established initial-access vector for follow-on intrusions. Organisations that have exposed the AMC directly to the internet, or where admin credentials may have been phished or reused, should treat this as a potential active compromise and initiate IR procedures in parallel with patching.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch first: SonicWall has released firmware updates for the SMA1000 series (SMA6210, SMA7210, SMA8200v). Affected versions are 12.4.3-03526 and 12.5.0 through 12.5.0-02952. Retrieve the exact patched build number and download link from the current SonicWall PSIRT advisory and deploy immediately.
- Restrict AMC access at the network layer: Block TCP 8443 (AMC default) from all sources except explicitly approved management workstations — enforce this at the perimeter firewall and on any internal VLAN ACL. The AMC must not be reachable from the internet.
- Audit and rotate administrator credentials: Enumerate all local and directory-bound (LDAP/RADIUS) admin accounts on the AMC; disable any that are not actively required, and rotate passwords for all remaining admin accounts immediately.
- Terminate and review active sessions: Review current AMC sessions for unfamiliar source IPs or off-hours timestamps; kill any suspicious sessions and flag source IPs for threat-intel lookup.
- Verify network segmentation: Confirm that SMA1000 appliances sit in a dedicated management VLAN with no lateral reachability from user-facing VLANs to the AMC interface.
Runbook · Step 2
Mitigation layers
- Network perimeter: Restrict TCP 8443 (and TCP 443 if the web UI is exposed) to a defined management IP allowlist via perimeter firewall and internal ACL. Limit outbound connections from the appliance to the internet to the minimum required — this disrupts reverse-shell callback channels.
- IPS/WAF rule: Enable IPS signatures for OS command injection patterns in HTTP POST requests targeting
/appliance/or/management/URI paths. Suricata/Snort: alert on special-character sequences (;,|,&&,$()) in AMC API request bodies (Content-Type:application/x-www-form-urlencodedor JSON). - Least-privilege / IAM hardening: Reduce the number of accounts holding the Administrator role on the AMC to the absolute minimum; enforce MFA for all admin logins where the firmware version supports it.
- Enhanced logging: Enable verbose logging on the AMC and ensure syslog forwarding to a central SIEM is active — prioritise authentication events and configuration-change records.
- Compensating monitoring: Until the patch is deployed, set up continuous monitoring for unexpected outbound connections or process activity originating from the appliance management IP (NetFlow/IPFIX anomaly detection or equivalent).
Runbook · Step 3
Detection rules
- Syslog / AMC audit log: Alert on admin logins followed by an abnormally high number of CLI commands or API calls within a short window. SPL:
index=sma sourcetype=sonicwall_sma action=login user_role=admin | transaction user maxspan=5m | where command_count > 10 - Network telemetry (Zeek/Suricata): Outbound TCP connections from the SMA1000 management IP to unknown external hosts following an admin authentication event — especially on non-standard ports (e.g. TCP 4444, 1337, 8080). Suricata rule:
alert tcp $SMA_MGMT_IP any -> $EXTERNAL_NET !443 (msg:"SMA1000 unexpected outbound post-auth"; flow:established,to_server; sid:9000001;) - Process telemetry (if agent-based visibility is available): Child processes of web-server or AMC processes (e.g.
nginx,java,python) spawning shell interpreters (/bin/sh,/bin/bash) — process ancestry chain:webserver → sh/bash. - SIEM correlation rule (Sigma shape):
title: SMA1000 AMC Post-Auth Command Injection Attempt logsource: product=sonicwall_sma detection: keywords: ['cmd_exec', 'shell', '/bin/sh', '&&', '|', ';'] condition: keywords - Authentication anomalies: Multiple admin logins from distinct source IPs within 10 minutes, or logins outside defined maintenance windows. KQL:
SonicWallLogs | where UserRole == "admin" and TimeGenerated > ago(10m) | summarize count() by SrcIP | where count_ > 3
Description
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Affected operating systems
other
sonicwall / sma6210_firmware
other
sonicwall / sma7210_firmware
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
12.5.0 – 12.5.0-0295212.4.3-03526fixed from 12.4.3-03526Metrics
Show all metrics
Weakness classes (CWE)
CWE-78Base
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-21 14:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica… → {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- CVE Modified2026-09-03 13:06 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica… → {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- CVE CISA KEV Update2026-09-02 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-09-02
- Due Date: 2026-09-02
- Required Action: 2026-09-02
- Vulnerability Name: 2026-09-02
- CVE Modified2026-09-02 18:21 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549
- SSVC: {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- CVE Modified2026-09-02 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-83549","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
Linked advisories
- csoonline2026-10-08 03:19 UTCSonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
- csoonline2026-09-02 23:22 UTCSonicWall reports two major security holes under active exploit
- securityweek2026-09-02 05:04 UTCSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
- cert-fr2026-09-02 00:00 UTCMultiples vulnérabilités dans les produits SonicWall (02 septembre 2026)