CVE-2026-4114Disclosure(sonicwall / sma6200)

LOWCVSS 6.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sonicwall sma6200 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-176

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sma6200
  • sma6200_firmware
  • sma6210
  • sma6210_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
sma6200sma6200_firmwaresma6210sma6210_firmwaresma7200sma7200_firmwaresma7210sma7210_firmwaresma8200v

1 version affected across 9 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-16: 1Mentions · 2026-05-17: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-16: 1Technical Details · 2026-05-17: 104-0904-1004-1605-17
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-101
Disclosure1
2026-04-161
Patch1
2026-05-171
General1
Full discourse5 posts
  • iototsecnews@iototsecnews
    Patch

    SonicWall SMA1000 の脆弱性 CVE-2026-4112 などが FIX:SQLi や権限昇格の恐れ https://iototsecnews.jp/2026/04/09/multiple-sonicwall-flaws-enable-sql-injection-and-privilege-escalation-attacks/ このセキュリティ・アドバイザリで対応されるのは、SonicWall の SMA1000 シリーズの入力データの処理方法に起因する複数の不備です。最も深刻な CVE-2026-4112 は、SQL コマンド内の特殊文字に対する不適切な無効化 (サニタイズ) に起因するものであり、読み取り専用の管理者にバックエンド・データベースの操作を許し、最上位の権限の奪取を引き起こします。また、Unicode の解釈ミスにより多要素認証 (MFA) の回避を許す CVE-2026-4114 / 4116 など、文字コードやレスポンス処理の甘さに起因する脆弱性も修正されています。ご利用のチームは、ご注意ください。 #CVE20264112 #CVE20264113 #CVE20264114 #CVE20264116 #SMA1000 #SonicWall #Vulnerability

    Post summary

    An advisory for SonicWall SMA1000 highlighting SQLi and privilege‑escalation flaws (CVE-2026-4112, 4114, 4116) and noting vendor fixes.

    01000105
    484 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-4112, CVE-2026-4113, CVE-2026-4114, CVE-2026-4116 SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003

    Post summary

    SonicWall announces that its SMA1000 Series Appliances are impacted by four new vulnerabilities (CVE‑2026‑4112, 4113, 4114, 4116).

    00010412
    6.8K followersView on X
  • Israel@f1tym1
    General

    CVE-2026-4114 | SonicWall SMA1000 AMC TOTP Authentication unicode encoding (SNWLID-2026-0003 / EUVD-2026-20906) https://ift.tt/7jbOAvh A vulnerability was found in SonicWall SMA1000. It has been declared as critical. Affected is an unknown function of the component AMC TOTP Au…

    Post summary

    The advisory announces a new critical CVE for SonicWall SMA1000, identifies the impacted component and the type of flaw, but provides no PoC, exploit, active exploitation, or patch information.

    0000052
    974 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4114 Remote Authenticated SSLVPN Admin AMC TOTP Authentication Bypass in SonicWall SMA1000 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4114

    Post summary

    The post announces a remote authenticated bypass vulnerability (CVE-2026-4114) affecting TOTP authentication in SonicWall SMA1000, providing technical details but no PoC, exploit code, or active exploitation evidence.

    0000056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4114 Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication. https://www.cve.org/CVERecord?id=CVE-2026-4114

    Post summary

    The post is a straightforward disclosure of CVE‑2026‑4114, detailing the Unicode encoding flaw that permits authenticated admin users to bypass TOTP authentication in SonicWall SMA1000 appliances. No PoC, exploit, or patch is referenced.

    00000152
    57.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
HWsonicwallsma6200---
OSsonicwallsma6200_firmware---
HWsonicwallsma6210---
OSsonicwallsma6210_firmware---
HWsonicwallsma7200---
OSsonicwallsma7200_firmware---
HWsonicwallsma7210---
OSsonicwallsma7210_firmware---
Appsonicwallsma8200v---

Explore more