CVE-2012-2626: SonicWall Scrutinizer

Medium severity, CVSS 5.0. EPSS: 44.5% chance of exploitation in the next 30 days.

cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.

Affected products

  • SonicWall Scrutinizer: before 9.5.0 (fixed in 9.5.0)

Published 2012-07-31. Last modified 2026-06-16.