GPU VulnDB

Database/Control plane, storage & DevOps

SonicWall SMA1000: authenticated admin can inject OS commands through the management console

CVE-2026-83549Control plane, storage & DevOpsKnown exploitedcurated

Impact

Under specific conditions the Appliance Management Console passes attacker-supplied input into an OS command, so an administrator of the appliance gets arbitrary command execution on the underlying system rather than only the operations the console exposes. That converts appliance administration into a shell on a device that terminates remote-access sessions and holds the credentials and certificates for them, and it defeats the assumption that a scoped admin account cannot reach the OS. CISA lists it as exploited in the wild, and it appears in the same advisory as the pre-authentication SSRF, so an attacker chaining the two has a plausible path from unauthenticated network access to code execution. The appliance is typically the way staff reach the fleet, so remediation and compromise both hit the same choke point.

Who can reach it

An attacker who already holds administrator credentials on the SMA1000 Appliance Management Console. Scored AV:L, so the vector assumes local or console-level access to the management interface rather than arbitrary internet reachability.

What to do

Apply the fixed build listed in SonicWall advisory SNWLID-2026-0016; the record does not name a version, so take it from the advisory. Appliance image upgrade plus reboot - do it per node of an HA pair with a failover between them, and expect session drops. Given the KEV listing, also rotate administrator credentials and review AMC access logs, since the exposure assumes an admin account that may already be in someone else's hands.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.