Description
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
Published: 2026-04-09
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper handling of Unicode encoding in the SSLVPN login flow of SonicWall SMA1000 appliances allows a remote authenticated administrator to skip the AMC TOTP challenge, effectively bypassing the second factor of authentication. This flaw is a classic example of CWE‑176, where incorrect interpretation of input data removes a security gate, enabling an attacker who already holds valid credentials to reach administrative control without the required one‑time password.

Affected Systems

All models within the SonicWall SMA1000 series are potentially affected because the advisory does not specify firmware or sub‑model details; therefore any appliance running the legacy firmware should be treated as at risk until a corrective update is applied.

Risk and Exploitability

The exploit requires possession of legitimate administrator credentials and is triggered remotely via the SSLVPN interface. The EPSS score of less than 1% and the absence from CISA’s KEV catalog suggest it is not yet a common target. However, the CVSS score of 6.6 reflects a medium severity coupled with the fact that bypassing MFA grants full administrative privileges, presenting a significant risk to confidentiality, integrity, and availability of the protected network.

Generated by OpenCVE AI on May 10, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the official SonicWall firmware update for the SMA1000 series as soon as it becomes available.
  • Discontinue or strongly restrict SSLVPN access from untrusted or remote networks until the patch is installed.
  • Enforce strict credential and MFA management policies, and monitor logs for irregular authentication activity.

Generated by OpenCVE AI on May 10, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 14 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall sma6200
Sonicwall sma6200 Firmware
Sonicwall sma6210
Sonicwall sma6210 Firmware
Sonicwall sma7200
Sonicwall sma7200 Firmware
Sonicwall sma7210
Sonicwall sma7210 Firmware
Sonicwall sma8200v
CPEs cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
Vendors & Products Sonicwall sma6200
Sonicwall sma6200 Firmware
Sonicwall sma6210
Sonicwall sma6210 Firmware
Sonicwall sma7200
Sonicwall sma7200 Firmware
Sonicwall sma7210
Sonicwall sma7210 Firmware
Sonicwall sma8200v

Sun, 10 May 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unicode Handling Enables MFA Bypass on SonicWall SMA1000

Sun, 10 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Mon, 13 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unicode Handling Enables MFA Bypass on SonicWall SMA1000

Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall sma1000
Vendors & Products Sonicwall
Sonicwall sma1000

Thu, 09 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
Weaknesses CWE-176
References

Subscriptions

Sonicwall Sma1000 Sma6200 Sma6200 Firmware Sma6210 Sma6210 Firmware Sma7200 Sma7200 Firmware Sma7210 Sma7210 Firmware Sma8200v
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-05-10T13:19:33.572Z

Reserved: 2026-03-13T11:57:22.758Z

Link: CVE-2026-4114

cve-icon Vulnrichment

Updated: 2026-04-13T13:00:25.765Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-09T15:16:13.817

Modified: 2026-05-14T19:37:22.150

Link: CVE-2026-4114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-10T16:00:13Z

Weaknesses