GPU VulnDB

Database/Control plane, storage & DevOps

SonicWall SMA1000: pre-auth SSRF via an unintended alternate access path in the Work Place interface

CVE-2026-83548Control plane, storage & DevOpsKnown exploitedcurated

Impact

An unauthenticated request to the Work Place interface reaches functionality that was meant to sit behind authentication, letting an attacker make the appliance issue requests and perform operations on their behalf. SonicWall scores it 10.0 with a scope change, meaning the compromise does not stop at the appliance - the SMA1000 sits at the edge with a route into the internal network, so its outbound request path is a way into management subnets that are otherwise unreachable from the internet. CISA lists it as exploited in the wild. For an operator, the appliance is usually the remote-access path staff use to reach the fleet, so both the exposure and the loss of it during an emergency upgrade land on the same critical piece of equipment.

Who can reach it

Anyone who can reach the SMA1000 Work Place interface over the network, unauthenticated. That interface is normally published to the internet by design.

What to do

Move to the fixed build named in SonicWall advisory SNWLID-2026-0016 - the record does not state a version, so take it from the advisory rather than assuming one. This is an appliance image upgrade and reboot, not a package update: schedule it per node of an HA pair, fail over between them, and expect established sessions to drop. Because the flaw is on the CISA KEV list, treat it as an emergency window and review appliance logs for prior exploitation rather than patching and moving on.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.