Database/Control plane, storage & DevOps
SonicWall SMA1000: authenticated admin can inject OS commands through the management console
Impact
Under specific conditions the Appliance Management Console passes attacker-supplied input into an OS command, so an administrator of the appliance gets arbitrary command execution on the underlying system rather than only the operations the console exposes. That converts appliance administration into a shell on a device that terminates remote-access sessions and holds the credentials and certificates for them, and it defeats the assumption that a scoped admin account cannot reach the OS. CISA lists it as exploited in the wild, and it appears in the same advisory as the pre-authentication SSRF, so an attacker chaining the two has a plausible path from unauthenticated network access to code execution. The appliance is typically the way staff reach the fleet, so remediation and compromise both hit the same choke point.
Who can reach it
An attacker who already holds administrator credentials on the SMA1000 Appliance Management Console. Scored AV:L, so the vector assumes local or console-level access to the management interface rather than arbitrary internet reachability.
What to do
Apply the fixed build listed in SonicWall advisory SNWLID-2026-0016; the record does not name a version, so take it from the advisory. Appliance image upgrade plus reboot - do it per node of an HA pair with a failover between them, and expect session drops. Given the KEV listing, also rotate administrator credentials and review AMC access logs, since the exposure assumes an admin account that may already be in someone else's hands.
References
Related entries
- CyberPower PowerPanel managed devices - shared device certificates: Every managed device uses an identical certificateCVE-2024-31410 · CyberPower PowerPanel managed devices - shared device certificatesHigh
- Keycloak: SAML signature scope determined by position, not ReferenceCVE-2024-8698 · KeycloakHigh
- Tridium Niagara Framework and Niagara Enterprise Security (before 4.10.11 / 4.14.2 / 4.15.1): A chain, not a singleCVE-2025-3937 · Tridium Niagara Framework and Niagara Enterprise Security (before 4.10.11 / 4.14.2 / 4.15.1)High
- BOSH vSphere CPI: missing certificate pinning lets an interceptor impersonate vCenter and capture admin credentialsCVE-2026-41012 · BOSH Director vSphere CPI (vCenter REST API certificate validation)High
- Dell OpenManage Server Administrator (improper authentication): An unauthenticated remote attacker gets unauthorizedCVE-2026-56793 · Dell OpenManage Server Administrator (improper authentication)High
- Ansible AWX: notification backends allow SSRF from the control node and leak webhook credentialsCVE-2026-71366 · Ansible AWX notification backends (webhook, Mattermost, Rocket.Chat, Grafana)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.