CVE-2026-83548

Summary

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Affected Software

VendorProductVersion RangeStatus
SonicWallSMA100012.4.3-03453 (platform-hotfix) and older versionsaffected
SonicWallSMA100012.5.0-02835 (platform-hotfix) and older versionsaffected

Weaknesses

  • CWE-918: CWE-918 Server-Side request forgery (SSRF)
  • CWE-441: CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: total

Additional References

References