CVE-2026-0516 PUBLISHED

Assigner: sonicwall
Reserved: 12.12.2025 Published: 05.08.2026 Updated: 05.08.2026

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

Product Status

Vendor SonicWall
Product SonicOS
Versions Default: unknown
  • Version 6.5.5.1-6n and older versions is affected
  • Version 7.0.1-5169 and older versions is affected
  • Version 7.3.3-7015 and older versions is affected
  • Version 8.2.1-8010 and older versions is affected

Credits

  • Joshua Chan finder

References

Problem Types

  • CWE-644 Improper neutralization of HTTP headers for scripting syntax CWE