Impact
An improper neutralization of special elements in user-supplied input allows an authenticated user with SuperAdmin privileges to inject arbitrary operating system commands via the On‑Prem Management interface of the SonicWall Network Security Manager. The injected commands are executed with the privileges of the underlying host, giving the attacker complete control over the device. This flaw enables the attacker to compromise confidentiality, integrity, and availability of the entire managed network.
Affected Systems
The vulnerability affects SonicWall Network Security Manager (NSM) On‑Prem installations. Specific affected versions are not enumerated in the advisory, so any current NSM deployment that still relies on the legacy On‑Prem interface should be reviewed.
Risk and Exploitability
The exploitation requires valid SuperAdmin credentials, so privileged access is a prerequisite. The EPSS score is 2%, and the lack of publicly disclosed exploits and the absence from the CISA KEV catalog indicate that widespread active exploitation is currently unlikely. Nevertheless, the potential impact is severe; once exploited, an attacker can execute arbitrary code on the host. Defensive measures should therefore be prioritized to prevent privileged users from having unnecessary exposure.
OpenCVE Enrichment