CVE-2026-15410
SonicWall SMA1000 Appliances Code Injection Vulnerability
Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Description as published by the source, in English.
Key facts
- Published
- 2026-07-14
- Last modified
- 2026-08-04
- Assigned by
- sonicwall
- Probability of exploitation
-
76.3 %
higher than 99 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-07-14, with a remediation deadline of 2026-07-17 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| SonicWall | SMA1000 (Linux) | ≥ 12.4.3-03245, ≤ 12.4.3-03434 | Affected |
| SonicWall | SMA1000 (Linux) | ≥ 12.5.0-02283, ≤ 12.5.0-02800 | Affected |
Weakness type
-
CWE-94: Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or b…
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1027.006: HTML Smuggling
- T1027.009: Embedded Payloads
- T1564.009: Resource Forking
References
Related at Berigo
Articles
-
Seven new KEV entries, three of them in open developer components
Same product
2026-09-03
CISA added seven new vulnerabilities to its Known Exploited Vulnerabilities catalogue on 2 September 2026. Three of them sit in open components used …
-
Urgent updates released for SonicWall SMA 100
Same product
2026-07-14
SonicWall has fixed several flaws in the SMA 100 series, including critical ones that may allow remote code execution.
-
Compromised VM gave attacker access to the entire ESXi host
Same product
2026-01-07
Huntress describes an intrusion where an attacker moved from one guest VM to all workloads on the ESXi host. Initial access likely came via a comprom…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.