CVE-2026-4112Disclosure(sonicwall / sma6200)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sonicwall sma6200 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sma6200
  • sma6200_firmware
  • sma6210
  • sma6210_firmware

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-09); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
sma6200sma6200_firmwaresma6210sma6210_firmwaresma7200sma7200_firmwaresma7210sma7210_firmwaresma8200v

1 version affected across 9 products

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 2Mentions · 2026-04-16: 1Mentions · 2026-05-17: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 1Technical Details · 2026-04-16: 1Technical Details · 2026-05-17: 104-0904-1004-1605-17
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure3
2026-04-102
Disclosure2
2026-04-161
Patch1
2026-05-171
Disclosure1
Full discourse7 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-4112 and other: SQL injection and TOTP vulnerabilities in SonicWall SMA 1000 Series, up to 7.2 rating ❗️ The most severe vulnerability (SQL injection) allows remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator. Search at http://Netlas.io: 👉 Link: https://nt.ls/mzseI 👉 Dork: http.favicon.hash_sha256:6bb6f64adaa6a7ed4da10a2fe4edf4cb4d9914aa742c7ad607ca4ca678dcd3f1 OR certificate.subject_dn:"HTTPS Management Certificate for SonicWALL (self-signed)" Vendor's advisory: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003

    Post summary

    The post outlines the SQL injection and TOTP vulnerabilities (CVE‑2026‑4112) in SonicWall SMA 1000 Series, their severity and impact, and references a vendor advisory, but offers no PoC, exploit code, or evidence of active exploitation.

    04062909
    7.5K followersView on X
  • iototsecnews@iototsecnews
    Patch

    SonicWall SMA1000 の脆弱性 CVE-2026-4112 などが FIX:SQLi や権限昇格の恐れ https://iototsecnews.jp/2026/04/09/multiple-sonicwall-flaws-enable-sql-injection-and-privilege-escalation-attacks/ このセキュリティ・アドバイザリで対応されるのは、SonicWall の SMA1000 シリーズの入力データの処理方法に起因する複数の不備です。最も深刻な CVE-2026-4112 は、SQL コマンド内の特殊文字に対する不適切な無効化 (サニタイズ) に起因するものであり、読み取り専用の管理者にバックエンド・データベースの操作を許し、最上位の権限の奪取を引き起こします。また、Unicode の解釈ミスにより多要素認証 (MFA) の回避を許す CVE-2026-4114 / 4116 など、文字コードやレスポンス処理の甘さに起因する脆弱性も修正されています。ご利用のチームは、ご注意ください。 #CVE20264112 #CVE20264113 #CVE20264114 #CVE20264116 #SMA1000 #SonicWall #Vulnerability

    Post summary

    This security advisory reports that SonicWall SMA1000 vulnerabilities (CVE‑2026‑4112, 4114, 4116) allow SQL injection, privilege escalation, and MFA bypass, and confirms that patches have been released to remediate these issues.

    01000105
    484 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-4112, CVE-2026-4113, CVE-2026-4114, CVE-2026-4116 SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003

    Post summary

    SonicWall announced that its SMA1000 series appliances are affected by CVE‑2026‑4112, 4113, 4114, and 4116, directing readers to a PSIRT page for further information.

    00010412
    6.8K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-4112 | SonicWall SMA1000 up to 12.4.3-03245/12.5.0-02283 sql injection (SNWLID-2026-0003 / EUVD-2026-20902) https://ift.tt/NoCzHOX A vulnerability labeled as critical has been found in SonicWall SMA1000 up to 12.4.3-03245/12.5.0-02283. Affected by this vulnerability i…

    Post summary

    CVE-2026-4112 is a critical SQL injection vulnerability affecting SonicWall SMA1000 firmware up to 12.5.0-02283; the post provides basic disclosure details but no evidence of exploitation, patch, or PoC.

    0000051
    974 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4112 SQL Injection in SonicWall SMA1000 Series Enables Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4112

    Post summary

    The provided text announces CVE-2026-4112 as an SQL injection vulnerability on SonicWall SMA1000 Series that can lead to privilege escalation, but it does not include a PoC, exploit code, active exploitation reports, or patch details.

    0000052
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4112 Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with … https://www.cve.org/CVERecord?id=CVE-2026-4112 ----- Traducción: CVE-2026-4112 Neu… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑4112, a remote authenticated SQL injection vulnerability in SonicWall SMA1000 appliances, with no PoC, exploit code, patch, or evidence of active exploitation.

    0000042
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4112 Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with … https://www.cve.org/CVERecord?id=CVE-2026-4112

    Post summary

    The snippet provides a brief disclosure of an SQL injection vulnerability in SonicWall SMA1000 appliances, offering only high-level technical details without PoC, exploit code, or mitigation information.

    00000141
    57.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
HWsonicwallsma6200---
OSsonicwallsma6200_firmware---
HWsonicwallsma6210---
OSsonicwallsma6210_firmware---
HWsonicwallsma7200---
OSsonicwallsma7200_firmware---
HWsonicwallsma7210---
OSsonicwallsma7210_firmware---
Appsonicwallsma8200v---

Explore more