SonicWall SMA 1000 (versions 12.4.3-03453 / 12.5.0-02835 and older)
A remote access gateway used by organisations to let employees connect securely to corporate networks from outside the office.
Root Cause
The flaw exists because the appliance does not properly restrict which internal resources the user-facing portal is permitted to reach. An unintended alternate access path allows requests to bypass the controls that should keep unauthenticated users out of sensitive functionality.
Attack Vector
An unauthenticated attacker sends a crafted request to the public-facing portal. The appliance processes it without checking whether the sender has any credentials, giving the attacker access to sensitive internal functions. When chained with CVE-2026-83549 (a separate authenticated OS command injection flaw in the admin console), the result is full remote code execution on a device sitting directly on the internet.
Detection Notes
Check for unexpected or repeated requests to internal portal endpoints from external IPs. Review admin console access logs for activity from unrecognised accounts. Look for anomalous outbound connections from the appliance itself.
Recommended Actions
- Upgrade immediately to firmware 12.4.3-03526 or 12.5.0-02952.
- If indicators of compromise are found, re-image hardware appliances or re-deploy virtual ones.
- Reset all user and administrator passwords and TOTP tokens after patching.

