CVE-2026-4112

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*

History

14 May 2026, 19:43

Type Values Removed Values Added
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003 - Vendor Advisory
CPE cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
First Time Sonicwall sma7200 Firmware
Sonicwall sma7210 Firmware
Sonicwall sma7200
Sonicwall sma7210
Sonicwall sma6210 Firmware
Sonicwall sma6200 Firmware
Sonicwall sma8200v
Sonicwall sma6200
Sonicwall sma6210
Sonicwall

10 May 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

09 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 15:16

Updated : 2026-05-14 19:43


NVD link : CVE-2026-4112

Mitre link : CVE-2026-4112

CVE.ORG link : CVE-2026-4112


JSON object : View

Products Affected

sonicwall

  • sma6200
  • sma6200_firmware
  • sma7200
  • sma6210
  • sma8200v
  • sma7210_firmware
  • sma6210_firmware
  • sma7200_firmware
  • sma7210
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')