Affected Systems
SonicWall SMA1000 appliances (models 6210, 7210, 8200v). Does not affect SSL-VPN on SonicWall firewalls or SMA 100 Series. Approximately 400+ appliances exposed online per Shadowserver tracking.
Exploitation Status
Actively exploited in the wild. Threat actors are chaining CVE-2026-83548 (SSRF-based command injection in WorkPlace interface, CVSS 10.0) with CVE-2026-83549 (command injection in Management Console requiring admin privileges) to achieve remote code execution.
Business Impact
Critical risk for organizations using SMA1000 for secure remote access. Successful exploitation grants attackers arbitrary OS command execution, enabling full appliance compromise. SMA1000 is deployed in large enterprises, government, and critical infrastructure. SonicWall has confirmed active exploitation but has not yet released IOCs or attack details. History of repeated zero-day exploitation in this product line (CVE-2026-15409/15410 in July, CVE-2025-40602 in December) with confirmed ransomware gang involvement.
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade all SMA1000 appliances (6210, 7210, 8200v) to the latest hotfix version released by SonicWall
- Audit SMA1000 appliances for indicators of compromise; if detected, re-image appliances per SonicWall guidance
- Force password resets for all user and administrator accounts on SMA1000 appliances and reset TOTP tokens
- Review authentication logs and Management Console access logs for unauthorized admin activity or anomalous SSRF patterns in WorkPlace interface
- Restrict network access to SMA1000 Management Console to trusted IP ranges and implement additional monitoring for command execution anomalies
