T The Triage ManualTechnical Guides for IT Emergencies
P1 · Remote Access & VPN

SonicWall SMA1000 Pre-Auth RCE via Chained SSRF + Command Injection (CVE-2026-83548, CVE-2026-83549) — Actively Exploited

Two chained vulnerabilities in SonicWall SMA1000 appliances (6210, 7210, 8200v) enable unauthenticated remote code execution. CVE-2026-83548 is a pre-auth SSRF (CVSS 10.0) in the Appliance Work Place interface that reaches the Appliance Management Console where CVE-2026-83549 (OS command injection) executes arbitrary commands. Exploitation preceded disclosure, requiring both patching to fixed platform-hotfix versions and post-compromise investigation on any previously exposed appliance.

Indicators

Likely causes

Diagnostic steps

  1. Log into each SMA1000 Appliance Management Console (AMC) and navigate to System > Status to record the current platform-hotfix version.
    Determine which appliances fall into the vulnerable version ranges (12.4.3-03453 and earlier; 12.5.0-02835 and earlier).
  2. Compare each appliance's running version against the fixed versions: 12.4.3-03526 platform-hotfix (12.4.3 branch) and 12.5.0-02952 platform-hotfix (12.5.0 branch).
    Confirm exposure to CVE-2026-83548 and CVE-2026-83549.
  3. Verify whether the Appliance Work Place interface is exposed to the internet by checking external firewall rules and running an external port scan against the appliance's public IP.
    Assess exploitability — if Work Place is internet-facing, assume potential compromise.
  4. Review network/edge firewall logs for unusual HTTP requests to the Work Place and AMC endpoints from external IPs, particularly high-volume requests or requests with unusual URI patterns.
    Look for signs of SSRF or command-injection attempts prior to patching.
  5. In Rapid7 Exposure Command, InsightVM, or Nexpose, run the vulnerability checks for CVE-2026-83548 and CVE-2026-83549 (available in the September 3rd content release).
    Programmatically confirm exposure across the SMA1000 fleet.
  6. Review AMC administrator accounts, recent configuration changes, and TOTP token activity for anomalies — check for new admin accounts, modified access policies, or unexpected TOTP enrollments.
    Identify potential post-exploitation persistence or credential misuse.
  7. Contact SonicWall Technical Support and request IOC review assistance for the affected appliance(s).
    Leverage vendor-side IOCs and forensic guidance since no public IOCs were available at time of publication.

Resolution path

Prevention

Tools

References

SonicWallSMA1000CVE-2026-83548CVE-2026-83549SSRFOS-command-injectionunauthenticated-RCEedge-applianceCISA-KEVactively-exploitedsecure-remote-accessVPNvulnerability-managementP1