
CVE-2026-4112 and other: SQL injection and TOTP vulnerabilities in SonicWall SMA 1000 Series, up to 7.2 rating ❗️ The most severe vulnerability (SQL injection) allows remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator. Search at http://Netlas.io: 👉 Link: https://nt.ls/mzseI 👉 Dork: http.favicon.hash_sha256:6bb6f64adaa6a7ed4da10a2fe4edf4cb4d9914aa742c7ad607ca4ca678dcd3f1 OR certificate.subject_dn:"HTTPS Management Certificate for SonicWALL (self-signed)" Vendor's advisory: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003
Post summary
The post outlines the SQL injection and TOTP vulnerabilities (CVE‑2026‑4112) in SonicWall SMA 1000 Series, their severity and impact, and references a vendor advisory, but offers no PoC, exploit code, or evidence of active exploitation.






