Back Heise.De Remote access Sonicwall SMA1000: Attackers are manipulating internal services
⚠️ English term and spelling x Two corrections: (1) SonicWall instead of Sonicwall (company spelling). (2) The English “Models” replaced by the German Modelle and the unsightly hyphen resolved in favor of a clean enumeration. Insert: SonicWall the SMA1000 models 6210, 7210 and 8200v ✓ Accept x Reject
Sonicwall’s SMA1000 remote access solution is vulnerable, and attackers are currently accessing instances with extensive privileges as part of active attacks. In one case, the hurdles for this are comparatively low. To protect systems, administrators must immediately install the available hotfixes. The extent of the attacks is currently unknown.
In a warning message, the developers list a “critical” vulnerability (CVE-2026-83548) with a maximum CVSS score of 10 out of 10 . The specific problem is a previously undocumented alternative access path in the Work Place interface of SMA1000 appliances.
According to the description of the vulnerability, a remote attacker can initiate an SSRF (Server-Side Request Forgery) attack without authentication, and this is exactly what is happening. This allows them to access services that are actually isolated. Access to administrative functions is also possible through this. For example, attackers can manipulate VPN configurations or gain persistent access. Additionally, code execution can occur. After that, systems are usually considered completely compromised.
To successfully exploit the second software vulnerability (CVE-2026-83549 “ high ”), attackers must already be authenticated. If so, they can execute their own code.
Sonicwall lists the SMA1000 models 6210, 7210, and 8200v as specifically affected by the vulnerabilities. The developers assure that the vulnerabilities have been closed in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix) . According to them, all versions are vulnerable.
Most recently, in July , attackers exploited critical security vulnerabilities in SMA1000 appliances.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
