Authenticated CLI command injection yields root on SonicWall Email Security
CVSS 3.1
7.8high
EPSS
<1%p10
Published
()
Modified
AI analysis
CVE-2026-66149 is a command injection flaw (CWE-94) in the SonicWall Email Security appliance, in the network interface update routine (updateNetIf per the ZDI advisory) that handles the netmask parameter. An attacker who is already authenticated and has access to the appliance's restricted CLI can pass a malicious netmask value, causing arbitrary operating system commands to be injected and executed. Because the injected commands run as root, the attacker gains full privilege escalation from the limited CLI context to complete control of the appliance, with high impact on confidentiality, integrity, and availability. All organizations running the affected SonicWall Email Security appliance are exposed, though only to users or attackers who can already reach the restricted CLI, making this primarily a local privilege escalation rather than a remote attack. There is currently no known public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.2%, indicating no confirmed exploitation in the wild at this time.
What to do: Update SonicWall Email Security appliances to the fixed release identified in SonicWall's PSIRT advisory (version numbers not provided in the available data), prioritizing appliances where non-administrators or scripts have restricted-CLI access. Until patched, limit restricted-CLI access to trusted administrators only and audit local accounts and any automation that touches interface configuration. Since this requires local authenticated access and there is no known exploitation, treat it as a high-severity but routine patching item rather than an emergency.
Affected
SonicWall Email Security (appliance)
—
Estimated exposure
moderatelikely on the order of tens of thousands of appliances deployed at organizations worldwide (estimate; SonicWall has not published an Email Security… — SonicWall is a large security vendor with hundreds of thousands of customers across its portfolio, but Email Security is one of its narrower appliance lines, so the deployed base is plausibly in the 10k–100k range; this is an inference,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
ZDI advisory ZDI-26-532 discloses CVE-2026-66149, a command injection in SonicWall Email Security updateNetIf allowing local privilege escalation (CVSS 7.8).
SonicWall Email Security contains a command injection flaw in the updateNetIf routine, tracked as CVE-2026-66149 with CVSS 7.8. A local attacker must first obtain the ability to execute low-privileged code on the target system in order to escalate privileges. The vulnerability was disclosed via ZDI advisory ZDI-26-532.