SonicWall SMA1000 Series Appliances Unicode TOTP Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing remote authenticated SSLVPN users to bypass Workplace or Connect Tunnel TOTP authentication has been identified in SonicWall SMA1000 series appliances. This issue arises from improper handling of Unicode encoding, affecting versions 12.4.3-03245 and earlier, as well as 12.5.0-02283 and earlier.

Impact

Exploitation of this vulnerability allows for bypassing TOTP authentication, potentially leading to unauthorized access to resources or functionalities that require TOTP verification.

Remediation

Users are advised to upgrade to SonicWall SMA1000 series versions 12.4.3-03387 or 12.5.0-02624 or higher. The latest platform-hotfix is available for download on mysonicwall.com.

Added: Apr 9, 2026, 3:40 PM
Updated: Apr 9, 2026, 3:40 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
5.4
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.