logo

Multiple SonicWall Vulnerabilities Enable SQL Injection and Privilege Escalation Attacks

ID: 747fc336-fb94-5ac5-9a3c-56317f5fd9b8

STIX ID: report--747fc336-fb94-5ac5-9a3c-56317f5fd9b8

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-21

Author: Abinaya

...
...

SonicWall published a critical advisory for four CVEs affecting SMA1000 appliances—most notably CVE‑2026‑4112 (CVSS 7.2) enabling SQL injection and privilege escalation, and CVE‑2026‑4114/4116 which allow TOTP/MFA bypasses—recommending immediate upgrade to patched firmware versions (12.4.3-03387+, 12.5.0-02624+) because no mitigations exist; SonicWall reports no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.