Authenticated CLI command injection to root in SonicWall Email Security via SNMP
CVSS 3.1
7.8high
EPSS
<1%p10
Published
()
Modified
AI analysis
CVE-2026-66150 is a code injection flaw (CWE-94) in the SonicWall Email Security appliance in which the restricted CLI improperly controls command generation for SNMP-related functions. An attacker who has already authenticated to the restricted CLI with low-level privileges can inject arbitrary operating system commands through the SNMP pathway, and those commands execute with root privileges. Successful exploitation therefore yields full compromise of the appliance — read, write, and availability impact as root — making it effectively a local privilege escalation from a restricted administrative account to total system control. Any organization running an on-premises SonicWall Email Security appliance is potentially exposed, though exploitation requires the attacker to first obtain authenticated CLI access, such as via a compromised or misused admin account. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days.
What to do: Track the SonicWall PSIRT advisory (CVE-2026-66150) and apply the patched firmware as soon as a fixed version is published. In the interim, limit restricted CLI access to trusted administrators, audit which accounts have CLI access for signs of compromise, and disable or restrict the SNMP service on the appliance if it is not required. Because exploitation requires prior authenticated CLI access, prioritize remediation on appliances where admin credentials may have been shared or exposed.
Affected
SonicWall Email Security appliance
—
Estimated exposure
moderatelikely on the order of tens of thousands of appliance deployments (roughly 10k–100k); no public install-base figure is available — SonicWall Email Security is an on-premises appliance product line sold mainly to SMB and mid-market organizations and is far smaller than SonicWall's firewall installed base, and no active-install or internet-exposed device counts appear…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
ZDI advisory ZDI-26-530 describes a command injection vulnerability in the snmp component of SonicWall Email Security, tracked as CVE-2026-66150 with a CVSS score of 7.8. Local attackers who can already execute low-privileged code on the target can escalate privileges on affected installations.