PatchSiren cyber security CVE debrief
CVE-2016-9682 Dell CVE debrief
CVE-2016-9682 describes two remote command injection flaws in the SonicWall Secure Remote Access server web administrative interface. The issue is in the diagnostics CGI at /cgi-bin/diagnostics, where attacker-controlled values are passed to system() without proper escaping. NVD classifies the flaw as CWE-77 and assigns a CVSS v3.0 score of 9.8, reflecting network reachability, no authentication, no user interaction, and full confidentiality, integrity, and availability impact.
- Vendor
- Dell
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-22
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-22
- Advisory updated
- 2026-05-13
Who should care
Organizations running SonicWall Secure Remote Access servers, especially teams responsible for perimeter appliance administration, vulnerability management, and incident response. Any environment exposing the web administrative interface should treat this as urgent.
Technical summary
According to the NVD record, the vulnerable product is SonicWall Secure Remote Access server version 8.1.0.2-14sv. The weakness is in the diagnostics CGI component used to email system-state information. Two variables named tsrDeleteRestartedFile and currentTSREmailTo are not properly escaped before being used in a system() call, allowing remote command injection. The NVD entry maps this to CWE-77 and lists the attack vector as network with no privileges or user interaction required.
Defensive priority
Critical: immediate remediation recommended for any exposed or untrusted-management-facing installation.
Recommended defensive actions
- Identify whether any SonicWall Secure Remote Access server instances are running the affected version 8.1.0.2-14sv or related vulnerable builds listed by the vendor.
- Apply the vendor remediation referenced in the Dell/SonicWall release notes and PSIRT advisory as soon as possible.
- Restrict access to the web administrative interface to trusted management networks until remediation is complete.
- Review appliance logs and system integrity for signs of unexpected command execution, shell access, or configuration changes.
- If compromise is suspected, treat the appliance as potentially fully exposed and follow incident response procedures, including credential and secret rotation where appropriate.
Evidence notes
The supplied NVD record identifies the vulnerable CPE as cpe:2.3:o:dell:sonicwall_secure_remote_access_server:8.1.0.2-14sv:*:*:*:*:*:*:* and assigns CVSS v3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It also lists CWE-77. The MITRE-imported references point to vendor release notes and the SonicWall PSIRT advisory for SNWLID-2016-0003. A third-party Exploit-DB reference is present in the corpus, but no exploit details are used here.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9682 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9682
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9682 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9682
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2016-0003
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/42342/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.