logo

Multiple SonicWall Flaws Enable SQL Injection and Privilege Escalation Attacks

ID: f91c9d5b-aa07-5ac1-afc7-bcb380576457

STIX ID: report--f91c9d5b-aa07-5ac1-afc7-bcb380576457

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Divya

...
...

SonicWall published a critical advisory for SMA1000 series appliances addressing four CVEs: CVE-2026-4112 (SQL injection enabling read-only admins to gain primary admin privileges), CVE-2026-4113 (credential enumeration), and CVE-2026-4114/CVE-2026-4116 (improper Unicode handling allowing TOTP bypasses). The vendor reports no active exploitation, warns that affected firmware versions must be patched immediately, and provides platform-hotfix versions 12.4.3-03387 and 12.5.0-02624 (or higher) as remedies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.