Sonicwall
Sonicwall Sma7210 Firmware: vulnerabilities and CVEs
Sonicwall Sma7210 Firmware has 10 published vulnerabilities, 9 of them in the last 12 months. 3 are rated critical and 6 are listed by CISA as actively exploited.
CVEs10
Last 12 months9
Critical3
Actively exploited6
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-83549 | High (7.8) | 11% | ⚠ Active exploitation | Sep 1, 2026 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific… |
| CVE-2026-83548 | Critical (10) | 8.8% | ⚠ Active exploitation | Sep 1, 2026 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to… |
| CVE-2026-15409 | Critical (10) | 6.8% | ⚠ Active exploitation | Jul 14, 2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to… |
| CVE-2026-15410 | High (7.2) | 12% | ⚠ Active exploitation | Jul 14, 2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a… |
| CVE-2025-40602 | Medium (6.6) | 2.8% | ⚠ Active exploitation | Dec 18, 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
| CVE-2025-23006 | Critical (9.8) | 23% | ⚠ Active exploitation | Jan 23, 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-83549 | High (7.8) | 11% | ⚠ Active exploitation | Sep 1, 2026 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific… |
| CVE-2026-83548 | Critical (10) | 8.8% | ⚠ Active exploitation | Sep 1, 2026 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to… |
| CVE-2026-15410 | High (7.2) | 12% | ⚠ Active exploitation | Jul 14, 2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a… |
| CVE-2026-15409 | Critical (10) | 6.8% | ⚠ Active exploitation | Jul 14, 2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to… |
| CVE-2026-4116 | High (7.2) | 0.71% | — | Apr 9, 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication. |
| CVE-2026-4114 | Medium (6.6) | 0.74% | — | Apr 9, 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication. |
| CVE-2026-4113 | High (7.2) | 0.60% | — | Apr 9, 2026 | An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials. |
| CVE-2026-4112 | High (7.2) | 0.53% | — | Apr 9, 2026 | Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate… |
| CVE-2025-40602 | Medium (6.6) | 2.8% | ⚠ Active exploitation | Dec 18, 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
| CVE-2025-23006 | Critical (9.8) | 23% | ⚠ Active exploitation | Jan 23, 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could… |