CVE-2026-83549
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Affected (6)
Products: Sonicwall: Sma8200v, Sma6210 Firmware, Sma7210 Firmware
Configuration A
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.4.3-03526 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma6210 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.4.3-03526 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma7210 | All versions |
References (2)
Source: PSIRT@sonicwall.com
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.