« Back to list

Sonicwall

Sonicwall Sma7210 Firmware: vulnerabilities and CVEs

Sonicwall Sma7210 Firmware has 10 published vulnerabilities, 9 of them in the last 12 months. 3 are rated critical and 6 are listed by CISA as actively exploited.

CVEs10
Last 12 months9
Critical3
Actively exploited6

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-83549High (7.8)11%⚠ Active exploitationSep 1, 2026
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific…
CVE-2026-83548Critical (10)8.8%⚠ Active exploitationSep 1, 2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to…
CVE-2026-15409Critical (10)6.8%⚠ Active exploitationJul 14, 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to…
CVE-2026-15410High (7.2)12%⚠ Active exploitationJul 14, 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a…
CVE-2025-40602Medium (6.6)2.8%⚠ Active exploitationDec 18, 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
CVE-2025-23006Critical (9.8)23%⚠ Active exploitationJan 23, 2025
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-83549High (7.8)11%⚠ Active exploitationSep 1, 2026
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific…
CVE-2026-83548Critical (10)8.8%⚠ Active exploitationSep 1, 2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to…
CVE-2026-15410High (7.2)12%⚠ Active exploitationJul 14, 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a…
CVE-2026-15409Critical (10)6.8%⚠ Active exploitationJul 14, 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to…
CVE-2026-4116High (7.2)0.71%—Apr 9, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
CVE-2026-4114Medium (6.6)0.74%—Apr 9, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
CVE-2026-4113High (7.2)0.60%—Apr 9, 2026
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
CVE-2026-4112High (7.2)0.53%—Apr 9, 2026
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate…
CVE-2025-40602Medium (6.6)2.8%⚠ Active exploitationDec 18, 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
CVE-2025-23006Critical (9.8)23%⚠ Active exploitationJan 23, 2025
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could…

Other products by Sonicwall