SonicWall SMA1000 Series Privilege Escalation Vulnerability via SQL Injection

Vulnerability

A SQL injection vulnerability has been identified in SonicWall SMA1000 series appliances, specifically in versions 12.4.3-03245 and earlier, as well as 12.5.0-02283 and earlier. This vulnerability allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling a user to gain primary administrator rights.

Remediation

Users are advised to upgrade to SonicWall SMA1000 version 12.4.3-03387 or higher, or version 12.5.0-02624 or higher. The latest platform-hotfix is available for download on mysonicwall.com.

Added: Apr 9, 2026, 3:46 PM
Updated: Apr 9, 2026, 3:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
5.0
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.