CVE-2026-0516

Summary

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

Affected Software

VendorProductVersion RangeStatus
SonicWallSonicOS6.5.5.2-28n and older versionsaffected
SonicWallSonicOS7.0.1-5169 and older versionsaffected
SonicWallSonicOS7.3.3-7015 and older versionsaffected
SonicWallSonicOS8.2.1-8010 and older versionsaffected

Weaknesses

  • CWE-644: CWE-644 Improper neutralization of HTTP headers for scripting syntax

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References