Sonicwall
Sonicwall Sma8200v: vulnerabilidades y CVE
Sonicwall Sma8200v tiene 10 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 3 son críticas y 6 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses9
Críticas3
Explotadas activamente6
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-83548 | Crítica (10) | 8.8% | ⚠ Explotación activa | 1 sept 2026 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to… |
| CVE-2026-83549 | Alta (7.8) | 11% | ⚠ Explotación activa | 1 sept 2026 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific… |
| CVE-2026-15409 | Crítica (10) | 6.8% | ⚠ Explotación activa | 14 jul 2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to… |
| CVE-2026-15410 | Alta (7.2) | 12% | ⚠ Explotación activa | 14 jul 2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a… |
| CVE-2025-40602 | Media (6.6) | 2.8% | ⚠ Explotación activa | 18 dic 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
| CVE-2025-23006 | Crítica (9.8) | 23% | ⚠ Explotación activa | 23 ene 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-83548 | Crítica (10) | 8.8% | ⚠ Explotación activa | 1 sept 2026 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to… |
| CVE-2026-83549 | Alta (7.8) | 11% | ⚠ Explotación activa | 1 sept 2026 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific… |
| CVE-2026-15410 | Alta (7.2) | 12% | ⚠ Explotación activa | 14 jul 2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a… |
| CVE-2026-15409 | Crítica (10) | 6.8% | ⚠ Explotación activa | 14 jul 2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to… |
| CVE-2026-4116 | Alta (7.2) | 0.71% | — | 9 abr 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication. |
| CVE-2026-4114 | Media (6.6) | 0.74% | — | 9 abr 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication. |
| CVE-2026-4113 | Alta (7.2) | 0.60% | — | 9 abr 2026 | An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials. |
| CVE-2026-4112 | Alta (7.2) | 0.53% | — | 9 abr 2026 | Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate… |
| CVE-2025-40602 | Media (6.6) | 2.8% | ⚠ Explotación activa | 18 dic 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
| CVE-2025-23006 | Crítica (9.8) | 23% | ⚠ Explotación activa | 23 ene 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.