SonicWall SMA1000 Command Injection CVE-2026-83549 Chained to Root
SonicWall SMA1000 has an OS command injection CVE-2026-83549 (CVSS 7.8) in the AMC console. Chained with pre-auth SSRF CVE-2026-83548 (CVSS 10.0), it allows root. CISA added it to KEV on September 2, 2026; fixes released September 1 in builds 12.4.3-03526 and 12.5.0-02952.
- CVE-2026-83549: command injection in AMC, CVSS 7.8, requires admin auth
- Chained with SSRF CVE-2026-83548 (CVSS 10.0) gives root on device
- Fixed builds: 12.4.3-03526 and 12.5.0-02952, no workarounds
- ZoomEye found 5,467 devices with SonicWall SMA1000 fingerprint
Read next
Security