CVE-2026-83548
SMA1000 Work Place pre-authentication SSRF exposes sensitive functionality (CVE-2026-83548)
SMA1000 has a pre-authentication SSRF in the Work Place interface (CVE-2026-83548). CVSS 3.1 score 10 critical; remote unauthenticated attackers can reach sensitive functionality. CISA KEV lists active exploitation. Apply the fixed builds listed below.
What happened
A pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. It is reachable over the network with low attack complexity, requires no privileges and no user interaction. A remote unauthenticated attacker can gain unauthorized access to sensitive functionality and perform unauthorized operations. CVSS 3.1 scores it 10 critical, with a scope change and high impact on confidentiality, integrity and availability.
CISA KEV lists this CVE as exploited, and CISA SSVC records exploitation as active. The CVE was added to KEV on 2 September 2026 with a due date of 5 September 2026.
Who is affected
Affected versions are SMA1000 12.4.3-03453 (platform-hotfix) and older versions, and 12.5.0-02835 (platform-hotfix) and older versions. The vulnerable component is the Work Place interface, so any deployment where that interface is reachable should be treated as affected. The CVE record does not map the SMA1000 version strings to specific hardware or virtual form factors.
What to do now
- Identify appliances running SMA1000 12.4.3-03453 (platform-hotfix) or older, or 12.5.0-02835 (platform-hotfix) or older.
- Apply the fixed builds: sma8200v 12.4.3-03526 or 12.5.0-02952; sma6210 firmware 12.4.3-03526 or 12.5.0-02952; sma7210 firmware 12.4.3-03526 or 12.5.0-02952.
- If you cannot apply a fixed build immediately, restrict network access to the Work Place interface. Follow CISA KEV’s required action, including applying vendor mitigations or discontinuing use of the product if mitigations are unavailable.
- Review whether the appliance is reachable from the internet and remove or restrict exposure where possible.
How to detect it
Start by confirming whether the SMA1000 Work Place interface is reachable from untrusted networks. Because the vulnerability is reachable without authentication, review administrative and configuration changes on the appliance for unexpected activity. The CVE record does not provide vendor-specific indicators of compromise.
Beyond the patch
Beyond applying the fixed builds, this is an exposure-management problem: a critical, pre-authentication network-reachable flaw on an appliance. CISA KEV lists active exploitation, so organisations with internet-reachable appliances should have detection and response in place. Our Managed Detection & Response (MDR) supports that need. Our Virtual CISO Services (vCISO) helps map and reduce internet-facing exposure so similar appliance issues are caught before exploitation.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| SMA1000 | 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions | No fixed version listed yet |