{
  "id": 8057102,
  "title": "SonicWall's Remediation Guidance Says the Patch Is Only Step One of Four",
  "url": "https://urgent.news/2026/09/17/sonicwalls-remediation-guidance-says-the-patch-is-only-step-one-of",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T14:04:00.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/sonicwalls-remediation-guidance-says-the-patch-is-only-step-one-of-four?source=rss"
  },
  "original_language": "en",
  "account": "SonicWall has issued remediation guidance for two vulnerabilities affecting its SMA 1000 secure remote access appliances. The first flaw, CVE-2026-83548, is a pre-authentication server-side request forgery vulnerability that allows a remote attacker to gain unauthorized access to sensitive functionality. The second flaw, CVE-2026-83549, is an OS command injection vulnerability that can be exploited by a remote attacker authenticated as an administrator to execute arbitrary OS commands. When combined, these vulnerabilities can lead to remote code execution. The vulnerabilities were discovered internally by SonicWall engineers William Perry and Adam Babis and affect models 6210, 7210, and 8200v of the SMA 1000 series appliances. Models 6210, 7210, and 8200v are affected, physical and virtual. The vulnerabilities were confirmed by the Cybersecurity and Infrastructure Security Agency (CISA) and are listed in the Known Exploited Vulnerabilities catalog. SonicWall recommends four steps to remediate the compromise: re-imaging the appliance if it's hardware, or redeploying it if it's virtual; changing all user and administrator passwords; resetting time-based one-time password (TOTP) tokens; and contacting SonicWall support for assistance in reviewing the system for indicators of compromise. An SSL VPN gateway is an authentication system with a network appliance, and an attacker gaining root access can copy the seed material used for second factor authentication. SonicWall has not publicly released indicators of compromise, which can make it difficult for defenders to determine if their systems have been compromised. It is recommended to treat the authentication material as exposed and rotate administrator and user passwords, as well as re-seed TOTP enrolments, on the same maintenance window as the hotfix. This approach is necessary due to the history of exploited zero-days affecting the SMA 1000 appliance line, which has occurred multiple times within a year.",
  "summary": "SonicWall confirmed two SMA 1000 zero-days under active exploitation. Its own remediation guidance ends with resetting TOTP tokens. Here's why that matters.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}