Affected Systems

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances: models 6210, 7210, and 8200v running versions 12.4.3-03453 and older, or 12.5.0-02835 and older. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF; CVE-2026-83549 (CVSS 7.8) is post-authentication command injection. Both vulnerabilities are being chained for remote code execution.

Exploitation Status

Active exploitation confirmed by SonicWall. Threat actors are chaining CVE-2026-83548 and CVE-2026-83549 to achieve unauthenticated remote code execution on vulnerable appliances. No public PoC available yet. Attacker identity and campaign details not disclosed.

Business Impact

Unauthenticated attackers can gain full control of internet-facing SMA 1000 VPN appliances, enabling credential theft, lateral movement, and persistent access to corporate networks. This is the second zero-day campaign targeting SMA 1000 devices in two months (previous campaign deployed KNUCKLEBALL malware). Organizations with unpatched appliances face immediate compromise risk.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately upgrade SMA 1000 appliances (models 6210, 7210, 8200v) to version 12.4.3-03526 or 12.5.0-02952 platform-hotfix
  • Review SMA 1000 system logs and appliance configurations for indicators of compromise, focusing on unauthorized access to Appliance Work Place interface and AMC command execution
  • If compromise is detected: re-image or re-deploy appliances, force reset all user and administrator passwords, and reset all TOTP tokens
  • Restrict management interface access to trusted IP ranges and implement additional network segmentation around VPN appliances
  • Monitor SonicWall PSIRT advisories for IoC publication and threat actor attribution updates