CVE-2026-4113
SonicWall SMA 8200v Appliance vulnerability analysis and mitigation

Overview

CVE-2026-4113 is an observable response discrepancy vulnerability (CWE-204) in SonicWall SMA1000 series appliances that allows a remote attacker to enumerate SSL VPN user credentials. It was published on April 9, 2026, by SonicWall and assigned a CVSS v3.1 base score of 7.2 (High) by CISA-ADP (GitHub Advisory, SonicWall PSIRT). Affected products include SMA6200, SMA6210, SMA7200, SMA7210 (firmware versions prior to 12.4.3-03387 or 12.5.0 through 12.5.0-02624), and SMA8200v (same version ranges) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-204 (Observable Response Discrepancy), meaning the SMA1000 appliance returns distinguishably different responses to authentication requests depending on whether a submitted username is valid or invalid. An attacker can exploit this remotely over the network without user interaction by systematically submitting authentication requests and analyzing response differences to identify valid VPN user accounts. Exploitation requires high privileges according to the CVSS vector, though the enumeration capability itself is the primary concern for credential harvesting. No public proof-of-concept code has been identified (SonicWall PSIRT, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to enumerate valid SSL VPN user accounts on affected SonicWall SMA1000 appliances by distinguishing server responses for valid versus invalid usernames. This information can be leveraged to conduct targeted brute-force or credential stuffing attacks against the VPN infrastructure, potentially leading to unauthorized access. While the vulnerability itself does not directly grant access, the enumerated credentials could facilitate lateral movement into internal networks protected by the VPN (SonicWall PSIRT, GitHub Advisory).

Exploitability

As of the time of reporting, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036% (0.000360), placing it in the 27th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported. Nessus plugin 305940 is available for detection (Tenable).

Exploitation steps

  1. Reconnaissance: Identify internet-facing SonicWall SMA1000 series appliances (SMA6200, SMA6210, SMA7200, SMA7210, SMA8200v) running firmware versions prior to 12.4.3-03387 or between 12.5.0 and 12.5.0-02624 using tools like Shodan or Censys, searching for SonicWall SSL VPN login portals.
  2. Baseline response capture: Send authentication requests with a known-invalid username and password to the SSL VPN login endpoint and capture the server's response (HTTP status code, response body, timing, or error message).
  3. Username enumeration: Systematically submit authentication requests with candidate usernames (from wordlists or OSINT-derived lists) and compare server responses to the baseline. Responses that differ in content, timing, or status code indicate a valid username.
  4. Credential list compilation: Compile the list of confirmed valid usernames for use in subsequent brute-force or credential stuffing attacks against the VPN portal.
  5. Follow-on attack: Use the enumerated valid usernames combined with common passwords or leaked credential databases to attempt unauthorized VPN authentication (SonicWall PSIRT, GitHub Advisory).

Indicators of compromise

  • Network: High volume of authentication requests to the SMA1000 SSL VPN login endpoint from a single or small set of external IP addresses; requests cycling through many different usernames with the same or no password.
  • Logs: VPN authentication logs showing repeated failed login attempts with varying usernames but consistent source IPs; unusual patterns of authentication failures that suggest systematic enumeration rather than organic user error.
  • Behavioral: Spike in authentication attempts outside of normal business hours; sequential or alphabetically ordered username submissions in authentication logs.

Mitigation and workarounds

SonicWall has released patched firmware versions addressing this vulnerability: 12.4.3-03387 and 12.5.0-02624 for all affected SMA1000 series appliances (SMA6200, SMA6210, SMA7200, SMA7210, SMA8200v). Organizations should upgrade to these versions immediately (SonicWall PSIRT). As interim mitigations, administrators should implement account lockout policies after a defined number of failed authentication attempts, monitor VPN authentication logs for enumeration patterns, restrict VPN access to known trusted IP ranges where feasible, and consider enabling multi-factor authentication to reduce the impact of credential enumeration.

Community reactions

The vulnerability received coverage from security news outlets including GBHackers and CyberSecurityNews, which reported on multiple SonicWall flaws disclosed around the same time, including SQL injection and privilege escalation issues (GBHackers, CyberSecurityNews). The Singapore Cyber Security Agency (CSA) issued an alert referencing the vulnerability (CSA Alert). Community discussion appeared on Reddit's r/sonicwall subreddit shortly after disclosure. Overall sentiment reflects routine concern about VPN appliance security given SonicWall's history as a target for threat actors.

Additional resources


SourceThis report was generated using AI

Related SonicWall SMA 8200v Appliance vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15409CRITICAL10
  • SonicWall SMA 8200v Appliance logoSonicWall SMA 8200v Appliance
  • cpe:2.3:a:sonicwall:sma8200v
YesNoJul 14, 2026
CVE-2026-15410HIGH7.2
  • SonicWall SMA 8200v Appliance logoSonicWall SMA 8200v Appliance
  • cpe:2.3:a:sonicwall:sma8200v
YesNoJul 14, 2026
CVE-2026-4116HIGH7.2
  • SonicWall SMA 8200v Appliance logoSonicWall SMA 8200v Appliance
  • cpe:2.3:a:sonicwall:sma8200v
NoYesApr 09, 2026
CVE-2026-4113HIGH7.2
  • SonicWall SMA 8200v Appliance logoSonicWall SMA 8200v Appliance
  • cpe:2.3:a:sonicwall:sma8200v
NoYesApr 09, 2026
CVE-2026-4114MEDIUM6.6
  • SonicWall SMA 8200v Appliance logoSonicWall SMA 8200v Appliance
  • cpe:2.3:a:sonicwall:sma8200v
NoYesApr 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management