Record summary

CVE-2026-0516 has a selected CVSS score of 6.5 (medium).

Description

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List6.5.5.2-28n and older versionsaffected
7.0.1-5169 and older versionsaffected
7.3.3-7015 and older versionsaffected
8.2.1-8010 and older versionsaffected

References

2