>samit_hota
Back to advisories

Security Advisory · SH-2026-166

CRITICALCVE-2026-83548CVSS 10.0OPEN

SonicWall Patches Critical Maximum-Severity SSRF Flaw in SMA1000 Series

Affected: SonicWall SMA1000 Appliances

Samit Hota·
#kev#sonicwall

SonicWall has addressed a maximum-severity Server-Side Request Forgery (SSRF) vulnerability in its enterprise remote access gateways. The flaw, designated as CVE-2026-83548, allows an unauthenticated, remote attacker to trigger arbitrary outbound requests from affected SonicWall SMA1000 Appliances, potentially exposing internal network resources and sensitive administrative functions.

Because SMA1000 devices sit directly at the perimeter to manage SSL VPN connections and secure remote access, an unauthenticated SSRF on these devices presents a severe operational risk.

Attack Path and the Impact of Scope Change

The issue stems from insufficient validation of user-supplied target URIs within the web application interface (categorized under CWE-918 and CWE-441). The vulnerability’s metric evaluation yields the maximum CVSS score of 10.0, driven by a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.

The key element in this rating is the Changed Scope (S:C). In an enterprise deployment, a scope change on a edge security gateway means an attacker can force the appliance to act as an unintended proxy. Without authenticating, a remote threat actor can instruct the SMA appliance to send HTTP/HTTPS requests to internal microservices, restricted localhost interfaces (127.0.0.1), or secondary control plane components that are isolated from the public internet.

In virtualized environment deployments, this SSRF mechanism can also be abused to target cloud provider infrastructure endpoints—such as Instance Metadata Services (IMDS)—to pull temporary IAM credentials, configuration files, or internal network mappings.

Evaluating Risk Beyond EPSS Metrics

Current telemetry places the Exploit Prediction Scoring System (EPSS) rating for CVE-2026-83548 at 0.27% (18.2th percentile). While a sub-1% EPSS score typically indicates low current activity in public honeypots, relying solely on this metric for perimeter SSL VPN appliances creates significant blind spots.

Perimeter remote-access hardware from vendors like SonicWall, Fortinet, and Ivanti remains a primary entry vector for sophisticated initial access brokers and ransomware affiliates. Weaponized SSRF vulnerabilities on internet-facing edge devices are rarely left unexploited once technical details circulate. Given that exploitation requires zero privileges (PR:N), low complexity (AC:L), and no user interaction (UI:N), the window between public disclosure and automated scanning is brief.

Affected Appliances and Remediation

SonicWall has released updated firmware versions to address SNWLID-2026-0016. Organizations running SMA 1000 series appliances—including the physical SMA 6210 and SMA 7210 appliances as well as the virtual SMA 8200v—must verify their current software releases and apply updates immediately.

The following version tracks require remediation:

  • 12.4.x Release Track: Upgrade SMA 8200v, SMA 6210, and SMA 7210 from versions prior to 12.4.3-03526 to 12.4.3-03526 or higher.
  • 12.5.x Release Track: Upgrade appliances running versions 12.5.0 through 12.5.0-02951 to 12.5.0-02952 or higher.

Administrators overseeing virtual deployments (SMA 8200v) on cloud infrastructure should ensure IMDSv2 (token-backed metadata service) is enforced with a hop limit of 1 to prevent SSRF-based metadata retrieval. Network security teams should also inspect system logs for anomalous outbound HTTP requests originating directly from the SMA appliance’s internal management interface toward internal IP ranges.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call