Executive brief
SonicWall SMA1000 series appliances are secure access gateways used to provide remote employees with encrypted connections to corporate resources. A vulnerability in how these devices handle specific text characters allows an already authenticated user to bypass secondary security checks (TOTP/Two-Factor Authentication). This could allow a user with compromised credentials to gain deeper access to the network without providing the required one-time security code.
Technical details
The vulnerability is classified as improper handling of Unicode encoding (CWE-176) within the SonicWall SMA1000 series firmware. It resides in the authentication processing logic for Workplace and Connect Tunnel components. A remote attacker who has already successfully completed the primary authentication phase can exploit this flaw to bypass the Time-based One-Time Password (TOTP) requirement. This bypass is achieved by supplying specially crafted Unicode strings that the appliance fails to process correctly during the multi-factor authentication (MFA) handshake. Patches have been released in firmware versions 12.4.3-03387 and 12.5.0-02624.
Affected products
- SonicWall SMA 6200 firmware < 12.4.3-03387, 12.5.0 < 12.5.0-02624
- SonicWall SMA 6210 firmware < 12.4.3-03387, 12.5.0 < 12.5.0-02624
- SonicWall SMA 7200 firmware < 12.4.3-03387, 12.5.0 < 12.5.0-02624
- SonicWall SMA 7210 firmware < 12.4.3-03387, 12.5.0 < 12.5.0-02624
- SonicWall SMA 8200v firmware < 12.4.3-03387, 12.5.0 < 12.5.0-02624
Timeline
- 2026-04-09: disclosed
- 2026-04-09: advisory: SonicWall PSIRT published SNWLID-2026-0003