CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2026-09-02. EPSS: 9.9% chance of exploitation in the next 30 days.

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Affected products

  • SonicWall SMA6210 Firmware: before 12.4.3-03526 (fixed in 12.4.3-03526); from 12.5.0, before 12.5.0-02952 (fixed in 12.5.0-02952)
  • SonicWall SMA7210 Firmware: before 12.4.3-03526 (fixed in 12.4.3-03526); from 12.5.0, before 12.5.0-02952 (fixed in 12.5.0-02952)
  • SonicWall SMA8200V: before 12.4.3-03526 (fixed in 12.4.3-03526); from 12.5.0, before 12.5.0-02952 (fixed in 12.5.0-02952)

Published 2026-09-01. Last modified 2026-09-21.