Improper Neutralization of HTTP Headers for Scripting Syntax in SonicOS - CVE-2026-0516
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect firewall management users to arbitrary web domains.
The vulnerability exists due to improper neutralization of HTTP headers for scripting syntax in the SonicOS web management interface when handling HTTP requests with a manipulated Host header. A remote attacker can send a specially crafted request to redirect firewall management users to arbitrary web domains.
User interaction is required for a firewall management user to follow the malicious redirection.