Description
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Control of Generation of Code, also known as code injection, is present in the SonicWall Email Security appliance. An attacker who has authenticated access to the restricted command-line interface can inject arbitrary operating system commands that are executed with root privileges through the netmask configuration. This flaw gives the attacker full control of the underlying host, allowing compromise, data exfiltration or pivoting to other systems on the network.

Affected Systems

SonicWall Email Security appliance

Risk and Exploitability

The CVSS base score of 7.8 indicates significant severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available. Because the flaw requires an authenticated session on the restricted CLI, the attack vector is local to the appliance, but once achieved, arbitrary OS commands run as root can lead to complete system compromise. Attackers could leverage the root privileges to install backdoors, exfiltrate data, or pivot to other network assets. Efforts to exploit this flaw are likely to be straightforward once privileged access is obtained, making the risk high for environments that expose the restricted CLI or lack proper network segmentation.

Generated by OpenCVE AI on August 12, 2026 at 14:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or firmware update that addresses the code injection vulnerability in the Email Security appliance.
  • Restrict access to the restricted command‑line interface to only trusted administrators and limit network exposure of the interface.
  • Place the appliance behind a firewall or network segmentation that restricts access to the restricted CLI to a trusted management subnet.

Generated by OpenCVE AI on August 12, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Improper Code Injection in SonicWall Email Security Appliance Enables Root Command Execution

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall email Security
Vendors & Products Sonicwall
Sonicwall email Security

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
Weaknesses CWE-94
References

Subscriptions

Sonicwall Email Security
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-12T04:00:41.899Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66149

cve-icon Vulnrichment

Updated: 2026-08-11T21:09:28.215Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T21:17:49.393

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-66149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T14:30:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')