【Security Vulnerability Alert】SonicWall NSM On-Prem and SMA1000 series contain multiple high-risk security vulnerabilities (CVE-2026-78327, CVE-2026-83548 and CVE-2026-83549)

 
2026/9/22 ~ 2027/3/22
View Count:37

Forwarded from National Information Security Analysis Center Security Information Alert NISAC-200-202609-00000008

[Content Description]
Researchers have discovered multiple high-risk security vulnerabilities (CVE-2026-78327, CVE-2026-83548 and CVE-2026-83549) in SonicWall NSM On-Prem and SMA1000 series, including OS Command Injection and Server-Side Request Forgery. Among them, CVE-2026-83548 and CVE-2026-83549 have been exploited by hackers. Please confirm and apply patches as soon as possible.

【CVE-2026-78327】 A remote attacker who has obtained administrative privileges can inject arbitrary OS commands through the management interface, thereby executing arbitrary code on the underlying host.

【CVE-2026-83548】 An unauthenticated remote attacker can access sensitive functions and perform unauthorized operations by exploiting an unintended alternative access path.

【CVE-2026-83549】 Under specific conditions, a remote attacker who has passed authentication can execute arbitrary OS commands as an administrator through the management console (AMC), thereby executing arbitrary code.

[Affected Platforms]
SonicWall NSM On-Prem (VMware, Hyper-V, Azure and KVM) versions 4.3.0 (inclusive) and earlier
 
SonicWall SMA1000 series (6210, 7210 and 8200v) platform-hotfix 12.4.3-03453 (inclusive) and earlier
 
SonicWall SMA1000 series (6210, 7210 and 8200v) platform-hotfix 12.5.0-02835 (inclusive) and earlier

[Recommended Measures]
The vendor has released security updates for the vulnerabilities. Please refer to the official instructions for updates. The URLs are as follows:
1. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015
2. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-78327
2. https://nvd.nist.gov/vuln/detail/CVE-2026-83548
3. https://nvd.nist.gov/vuln/detail/CVE-2026-83549

Files
None
Top↑