EUVD Vulnerability Catalog
Actively Exploited (KEV)
EUVD-2026-69707
Severity: HIGH
Base Score: 7.8
CVSS Version: 3.1
Vulnerability Description
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Local
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): Low
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
SonicWall
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
sonicwall
EPSS Probability
0
Known Aliases
CVE-2026-83549
GHSA-vxcc-7cf2-wcgh
Published On
2026-09-01
Last Updated
2026-09-02
Exploited Since
2026-09-02