CVE-2026-4116

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*

History

14 May 2026, 19:33

Type Values Removed Values Added
First Time Sonicwall sma7200 Firmware
Sonicwall sma7210 Firmware
Sonicwall sma7200
Sonicwall sma7210
Sonicwall sma6210 Firmware
Sonicwall sma6200 Firmware
Sonicwall sma8200v
Sonicwall sma6200
Sonicwall sma6210
Sonicwall
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003 - Vendor Advisory
CPE cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:*

13 Apr 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

09 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 15:16

Updated : 2026-05-14 19:33


NVD link : CVE-2026-4116

Mitre link : CVE-2026-4116

CVE.ORG link : CVE-2026-4116


JSON object : View

Products Affected

sonicwall

  • sma6200
  • sma6200_firmware
  • sma7200
  • sma6210
  • sma8200v
  • sma7210_firmware
  • sma6210_firmware
  • sma7200_firmware
  • sma7210
CWE
CWE-176

Improper Handling of Unicode Encoding