---
id: CVE-2026-83549
title: >-
  Post-authentication Improper Neutralization of Special Elements used in an OS
  Command ('OS Command Injection') vulnerability has been identified in the
  SMA1000 Appliance Management Console (AMC) which in specific conditions could
  potenti…
summary: >-
  Post-authentication Improper Neutralization of Special Elements used in an OS
  Command ('OS Command Injection') vulnerability has been identified in the
  SMA1000 Appliance Management Console (AMC) which in specific conditions could
  potenti…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: sonicwall
product: sma8200v
affected:
  - sma8200v < 12.4.3-03526
  - 'sma8200v >= 12.5.0, < 12.5.0-02952'
  - sma6210_firmware < 12.4.3-03526
  - 'sma6210_firmware >= 12.5.0, < 12.5.0-02952'
  - sma7210_firmware < 12.4.3-03526
  - 'sma7210_firmware >= 12.5.0, < 12.5.0-02952'
patched:
  - sma8200v 12.5.0-02952
  - sma6210_firmware 12.5.0-02952
  - sma7210_firmware 12.5.0-02952
published: '2026-09-01'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T14:17:21.703'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83549'
references:
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016'
    label: PSIRT@sonicwall.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.08505
epssPercentile: 0.94859
kev: true
kevDateAdded: '2026-09-02'
kevDueDate: '2026-09-05'
kevRansomware: false
exploited: true
exploits:
  metasploit:
    - exploit/linux/http/sonicwall_sma1000_couchdb_rce
  checkedAt: '2026-09-21T14:39:31.025Z'
exploitAvailable: true
zeroDay: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-03T03:55:31.034713Z'
ingestedAt: '2026-09-21T13:37:22.847Z'
---

## Overview

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

## Affected

- `sma8200v < 12.4.3-03526`
- `sma8200v >= 12.5.0, < 12.5.0-02952`
- `sma6210_firmware < 12.4.3-03526`
- `sma6210_firmware >= 12.5.0, < 12.5.0-02952`
- `sma7210_firmware < 12.4.3-03526`
- `sma7210_firmware >= 12.5.0, < 12.5.0-02952`

## Remediation

Upgrade past the affected range:

- `sma8200v 12.5.0-02952`
- `sma6210_firmware 12.5.0-02952`
- `sma7210_firmware 12.5.0-02952`
