logo

SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses

ID: 7a5eb91c-54f7-5074-ad6f-432df840e249

STIX ID: report--7a5eb91c-54f7-5074-ad6f-432df840e249

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** SonicWall released patches addressing four vulnerabilities in SMA 1000 series appliances (CVE-2026-4112, CVE-2026-4113, CVE-2026-4114, CVE-2026-4116), the most severe being a CVSS 7.2 SQL injection that allows a remote authenticated user with read-only admin privileges to escalate to primary administrator; two Unicode-based TOTP MFA bypasses let authenticated SSLVPN users or admins bypass TOTP, and an observable response discrepancy can be used to enumerate SSL VPN credentials; SonicWall urges immediate upgrade to fixed releases and reports no observed in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.