Urgent.News

What's breaking now, across thousands of outlets.

Tech

SonicWall's Remediation Guidance Says the Patch Is Only Step One of Four

SonicWall confirmed two SMA 1000 zero-days under active exploitation. Its own remediation guidance ends with resetting TOTP tokens. Here's why that matters.

SonicWall's Remediation Guidance Says the Patch Is Only Step One of Four

SonicWall has issued remediation guidance for two vulnerabilities affecting its SMA 1000 secure remote access appliances. The first flaw, CVE-2026-83548, is a pre-authentication server-side request forgery vulnerability that allows a remote attacker to gain unauthorized access to sensitive functionality. The second flaw, CVE-2026-83549, is an OS command injection vulnerability that can be exploited by a remote attacker authenticated as an administrator to execute arbitrary OS commands.

When combined, these vulnerabilities can lead to remote code execution. The vulnerabilities were discovered internally by SonicWall engineers William Perry and Adam Babis and affect models 6210, 7210, and 8200v of the SMA 1000 series appliances. Models 6210, 7210, and 8200v are affected, physical and virtual. The vulnerabilities were confirmed by the Cybersecurity and Infrastructure Security Agency (CISA) and are listed in the Known Exploited Vulnerabilities catalog.

SonicWall recommends four steps to remediate the compromise: re-imaging the appliance if it's hardware, or redeploying it if it's virtual; changing all user and administrator passwords; resetting time-based one-time password (TOTP) tokens; and contacting SonicWall support for assistance in reviewing the system for indicators of compromise.

An SSL VPN gateway is an authentication system with a network appliance, and an attacker gaining root access can copy the seed material used for second factor authentication. SonicWall has not publicly released indicators of compromise, which can make it difficult for defenders to determine if their systems have been compromised.

It is recommended to treat the authentication material as exposed and rotate administrator and user passwords, as well as re-seed TOTP enrolments, on the same maintenance window as the hotfix. This approach is necessary due to the history of exploited zero-days affecting the SMA 1000 appliance line, which has occurred multiple times within a year.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

SSH Tunnel Manager in Rust: CLI vs Native GUI Trade-offs

🔧 The Problem A few weeks ago a Swift-based macOS SSH tunnel manager started making the rounds here — a menu bar app that lets you spin up local/remote port forwards without touching a terminal.

  • GUI version provides visual status indicators and native features like macOS keychain integration
  • GUI incurs distribution complexity with unsigned builds needing Gatekeeper and SmartScreen warnings

Cómo solucionar el error “Enable JavaScript and cookies to continue”

Cómo solucionar el error “Enable JavaScript and cookies to continue” Este mensaje aparece cuando Cloudflare (u otro proxy de seguridad similar) detecta que el navegador del usuario no cumple con los…

  • Ensure JavaScript is enabled in browser
  • Allow cookies in browser settings
  • Use JavaScript evasion techniques for automation

More from Thursday 17 September →