CVE-2026-4116 is a Unicode encoding handling flaw affecting SonicWall SMA1000 series appliances that enables authenticated SSLVPN users to circumvent TOTP authentication on Workplace/Connect Tunnel functions. The vulnerability carries a CVSS score of 7.2 (High) with a network-based attack vector requiring high privilege credentials and no user interaction, potentially resulting in complete compromise of confidentiality, integrity, and availability. Exploitation status indicates low current threat activity, with no evidence of active exploitation in the wild, no documented public exploits, and minimal community attention reflected by its position in the lower percentile of vulnerability severity rankings. The moderate FAUCET Risk Score of 47.0 suggests this warrants patching but is not among the most critical threats requiring immediate intervention. Organizations running affected SonicWall appliances should prioritize applying available patches, particularly if supporting high-value remote access scenarios where authentication bypass could enable lateral movement or data exfiltration.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.4.3-03387CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:* | ||
>= 12.5.0, < 12.5.0-02624CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:* | ||
< 12.4.3-03387CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:* | ||
>= 12.5.0, < 12.5.0-02624CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:* | ||
< 12.4.3-03387CPE matchmatch criteria | cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.