← Vulnerability feed

Vulnerability record · CVE-2012-2626 · published 31 July 2012

CVE-2012-2626: Sonicwall scrutinizer improper authentication vulnerability

Sonicwall · Scrutinizer

cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.

5.0 CVSS 2.0 Medium EPSS 44% · top 1.3% CWE-287 · Improper authentication
5.0CVSS 2.0 base score
44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2626 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2012-2627Sonicwall scrutinizer vulnerabilityd4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrit…EPSS 5.7%7.5CVE-2012-3951Plixer Scrutinizer default admin password enables SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and…EPSS 52%analysed6.5CVE-2014-4977Dell SonicWall Scrutinizer SQL injection in admin and exporter endpointsDell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such…EPSS 75%analysed6.5CVE-2012-2962Plixer Scrutinizer statusFilter.php SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is p…EPSS 67%analysed5.5CVE-2014-4976Sonicwall scrutinizer permissions and access controls vulnerabilityDell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…EPSS 2.7%4.3CVE-2012-3848Sonicwall scrutinizer cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remo…EPSS 2.5%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed

Source: NIST National Vulnerability Database (record CVE-2012-2626), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.