CVE-2023-0126: SonicWall SMA1000 Firmware

High severity, CVSS 7.5. EPSS: 72.7% chance of exploitation in the next 30 days.

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.

Affected products

  • SonicWall SMA1000 Firmware: version 12.4.2 only

Published 2023-01-19. Last modified 2026-06-17.