🔴 CVE-2026-83548

CVE-2026-83548 is a pre-authentication SSRF vulnerability in the SonicWall SMA1000 Work Place interface, exploitable remotely without authentication or user interaction, with a maximum CVSS score of 10.0. It is actively exploited in the wild and listed in CISA KEV, allowing unauthenticated attackers to reach internal sensitive functionality via an unintended alternate access path, effectively compromising the appliance itself.

← Back to Overview
HIGH_RISK
Risk Level
10.0
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-01

Added to CISA KEV: 2026-09-02 1 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-83548 is a critical, pre-authentication Server-Side Request Forgery (SSRF) vulnerability affecting the Work Place interface of SonicWall SMA 1000 series appliances [2][4]. This flaw arises from an unintended alternate access path within the appliance's interface, allowing remote, unauthenticated attackers to interact with internal, sensitive functionality [1][8]. With a CVSS score of 10.0, it represents a severe security risk that enables unauthorized operations, potentially compromising the integrity and security of both the appliance and the connected internal network [2][7].

Exploitation

  • Active Exploitation: The vulnerability has been identified as being actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog [6][7].
  • Attack Prerequisites: Exploitation is possible remotely over the network without requiring any authentication or user interaction [2][4].
  • Tooling/PoC: While proof-of-concept information is available via security intelligence feeds, specific public exploit tools have facilitated the observed active campaigns [1][7].

Affected Products & Patches

  • Affected Products: SonicWall SMA 1000 series appliances, specifically models 6210, 7210, and 8200v [2].
  • Remediation: SonicWall advises that affected appliances must be re-imaged (for hardware) or re-deployed (for virtual appliances) [3].
  • Mitigation: Organizations are strongly advised to change all user and administrator passwords and reset TOTP tokens following the remediation process [3].

Impact

  • Unauthorized Access: Successful exploitation allows attackers to gain unauthorized access to sensitive internal functionality and perform operations on the appliance [1].
  • Potential Consequences: The vulnerability may permit reading sensitive data, modifying system configurations, or potentially executing commands on the appliance and internal network systems [1].
  • Business Risk: For internet-facing deployments, the risk is severe, as the appliance provides a direct, unauthenticated entry point into the internal network, significantly increasing the likelihood of widespread system compromise and data breach [5][7].

Sources

  1. CVE-2026-83548 - Exploits & Severity - Feedly

    CVE info copied to clipboard. Summary. Pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface due to an unintended alternate access path that allows unauthorized access to sensitive functionality. Impact. An unauthenticated attacker over the network can exploit this SSRF…

  2. SonicWall SMA1000 vulnerabilities (CVE-2026-83548...) | SOPHOS

    On September 1, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. CVE-2026-83548 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface. According…

  3. Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities ...

    Re-image (hardware) or re-deploy (virtual) appliances. Change all user and administrator passwords. Reset TOTP tokens. SonicWall strongly advises Secure Mobile Access customers on affected versions follow the guidance provided. Related information SNWLID-2026-0016 CVE-2026-83548 CVE-2026-83549 How t…

  4. CVE-2026-83548 : SSRF Vulnerability in SMA1000 Appliance Work...

    CVE-2026-83548 is a significant vulnerability identified in the SonicWall SMA1000 Appliance Work Place Interface, specifically characterized as a Server-Side Request Forgery (SSRF) issue. This vulnerability arises due to an unintended alternate access path that allows remote unauthenticated attacker…

  5. NVD-CVE-2026-83548 - NIST

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. ... CVE-2026-83548 Detail Description A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate a…