Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-83548: SMA1000 Workplace Interface lets remote attacker access internal services

CVE-2026-83548 · published 1 day ago · actively exploited
Summary

The SMA1000 appliance’s Workplace web page can be reached without logging in, and it can be tricked into contacting other parts of your network. An attacker outside your organization could use this to reach sensitive functions or data inside your system. Apply the vendor’s security update or block external access to the Workplace interface until it is patched.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
sonicwall sma1000 appliances All versions
sonicwall sma8200v < 12.4.3-03526
>= 12.5.0, < 12.5.0-02952
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
sonicwall sma6210_firmware < 12.4.3-03526
>= 12.5.0, < 12.5.0-02952
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
sonicwall sma7210_firmware < 12.4.3-03526
>= 12.5.0, < 12.5.0-02952
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
sonicwall sma1000 12.4.3-03453 (platform-hotfix) and older versions
Original advisory text
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Severity
10.0 Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
Timeline
Published1 Sep 2026
Updated3 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-83548 · MITRE
CVE-2026-83548 · CISA KEV
Monitor software like this
Free during beta