CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Published Sep 1, 2026
·Updated
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Other sources
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
— CISA
Affected Software
11 affected components
SMA1000 Appliance Work Place interface
SonicWall SMA1000 Appliances
All of the following
Any of the following
SonicWall Sma8200v<12.4.3-03526
SonicWall Sma8200v>=12.5.0<12.5.0-02952
SonicWall Sma8200v
All of the following
Any of the following
SonicWall Sma6210 Firmware<12.4.3-03526
SonicWall Sma6210 Firmware>=12.5.0<12.5.0-02952
SonicWall Sma6210
All of the following
Any of the following
SonicWall Sma7210 Firmware<12.4.3-03526
SonicWall Sma7210 Firmware>=12.5.0<12.5.0-02952
SonicWall Sma7210
Event History
Sep 1, 2026
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
DescriptionWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeaknessAffected Software
Sep 2, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
News Published
via BleepingComputer·06:39 AM
News Published
via BleepingComputer·06:44 AM