

Affected Environment
SonicWall SMA1000 appliances (models 6210, 7210, 8200v), versions 12.4.3-03453 and 12.5.0-02835 and earlier.
Threat Overview
Actively exploited SSRF flaw and a post-authentication OS command injection threaten SMA1000 Work Place and Management Console.
Exposure Timeline
Exploitation confirmed in the wild; fixed platform-hotfix versions already available and should be applied immediately.
Attack Surface
Unauthenticated SMA1000 Work Place interface and authenticated Appliance Management Console, both exposed to remote network attackers.
Technical Root Cause
An unintended alternate access path enables pre-auth SSRF; improper command neutralization allows authenticated OS command injection.
Exploitation Pathway
Attacker abuses SSRF to reach unauthorized functionality, then leverages an admin session to inject OS commands for remote code execution.
Operational Impact
Unauthorized access to sensitive functionality, and potential remote code execution, on exposed SMA1000 appliances.
Strategic Impact
Critical risk for large and medium organizations; high risk for smaller government and business entities.
Required Mitigation
Upgrade to fixed hotfix versions 12.4.3-03526 or 12.5.0-02952, or later, immediately after testing.
Incident Response Guidance
Review Work Place and Management Console access logs, apply network filtering, and conduct penetration testing per CIS safeguards.
References
SonicWall PSIRT Advisory, BleepingComputer.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




