Description
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.
Published: 2026-08-11
Score: 6.3 Medium
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated command injection flaw in the Command‑Line Interface of SonicWall GMS versions 9.5.1 and earlier lets a low‑privileged local user run arbitrary system commands with root privileges. The weakness, classified as CWE‑94, permits attackers to inject shell commands that are executed in the context of the operating system, effectively bypassing normal access controls.

Affected Systems

Vulnerable products are SonicWall GMS command‑line interface software release 9.5.1 (Build 9510.1044) and all earlier releases. The flaw applies to any installation that allows local users to authenticate to the CLI.

Risk and Exploitability

The CVSS base score of 6.3 indicates a moderate level of severity, but the EPSS score of 1% suggests that exploitation is not yet highly common. The vulnerability is not listed in CISA’s KEV catalog. Because the attack requires local authenticated access, it poses a risk primarily to individuals with physical or console access, yet compromised local users can elevate to root, potentially enabling full system takeover. The likelihood of exploitation remains limited to environments where local CLI access is available but it should be considered a high‑impact risk once the flaw is discovered by a threat actor.

Generated by OpenCVE AI on August 13, 2026 at 02:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the SonicWall website or contact support for firmware or patch updates that address the CLI command injection flaw.
  • If an upgrade is not immediately possible, restrict local user accounts from accessing the CLI or completely disable the CLI service on untrusted nodes.
  • Ensure that physical and network access to the device is tightly controlled, and monitor for anomalous command‑line activity.

Generated by OpenCVE AI on August 13, 2026 at 02:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall gms
Vendors & Products Sonicwall
Sonicwall gms

Thu, 13 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Authenticated Command Injection in SonicWall GMS CLI Enables Local Privilege Escalation

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.
Weaknesses CWE-94
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-11T21:11:09.052Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66148

cve-icon Vulnrichment

Updated: 2026-08-11T21:11:06.315Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T21:17:49.287

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-66148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:42Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')