CVE-2026-4114
medium
CVSS v3
6.6
CVSS v2
—
VIR risk
6.6
Description
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: PSIRT@sonicwall.com — https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| sonicwall | sma8200v | {"endExcluding":"12.4.3-03387"} | 12.4.3-03387 |
References
CWEs
CWE-176
Verify integrity in audit chain (admin only). AS-IS.