Description:
Forwarded Security Alert from TWCERT/CC (Taiwan Computer Emergency Response Team/Coordination Center) Alert ID: TWCERTCC-200-202609-00000001
SonicWall has issued a critical security vulnerability advisory (CVE-2026-83548, CVSS: 10.0) for its SMA1000 series products. This Server-Side Request Forgery (SSRF) vulnerability exists in the management interface of SMA1000 series devices. An unauthenticated remote attacker could exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized actions.
Note: SonicWall PSIRT has investigated a case indicating active exploitation of this vulnerability. It is recommended to apply temporary mitigation measures immediately to prevent potential attacks targeting this vulnerability.
Affected Systems:
SMA1000 Models - 6210, 7210, 8200v firmware versions 12.4.3-03453 and earlier
SMA1000 Models - 6210, 7210, 8200v firmware versions 12.5.0-02835 and earlier
Recommendations:
Please update to the following versions or later:
SMA1000 Models - 6210, 7210, 8200v firmware versions 12.4.3-03526 and later
SMA1000 Models - 6210, 7210, 8200v firmware versions 12.5.0-02952 and later
References:
-
Computer and Communication Center
Network System Division