CVE-2026-83548

Analyzed
Published: 01 Sept 2026, 21:25
Last modified:02 Sept 2026, 19:58

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 CRITICAL
v3.1 (cve.org)
EPSS Score
0.27% LOW
0% probability
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Sept 2026, 21:25
Published
Vulnerability first disclosed
02 Sept 2026, 00:00
Added to CISA KEV
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
02 Sept 2026, 19:58
Last Modified
Vulnerability information updated
05 Sept 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CVSS Metrics

  • v3.1CRITICALScore: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.27% Percentile: 18%

Techniques & Countermeasures

  • CWE-441Unintended Proxy or Intermediary ('Confused Deputy')

    The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

  • CWE-918Server-Side Request Forgery (SSRF)

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Systems

  • sonicwallsma1000

    12.4.3-03453 (platform-hotfix) and older versions | 12.5.0-02835 (platform-hotfix) and older versions

  • sonicwallsma6210_firmware

    < 12.4.3-03526 | ≥ 12.5.0, < 12.5.0-02952

  • sonicwallsma7210_firmware

    < 12.4.3-03526 | ≥ 12.5.0, < 12.5.0-02952

  • sonicwallsma8200v

    < 12.4.3-03526 | ≥ 12.5.0, < 12.5.0-02952

References (2)