HomeDefault status
unknown
12.4.3-03245 (platform-hotfix) and earlier versions.
affected
12.5.0-02283 (platform-hotfix) and earlier versions.
affected
Description
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
Problem types
CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
Product status
12.4.3-03245 (platform-hotfix) and earlier versions.
12.5.0-02283 (platform-hotfix) and earlier versions.
References
psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003