Junglewise Threat Intelligence

CVE-2026-15410: SonicWall SMA1000 code injection in Appliance Management Console

CVE-2026-15410 · Severity: critical · Exploited in the wild · Published 2026-07-14

Executive brief

A security vulnerability has been identified in the management console of SonicWall SMA1000 series appliances, which are used to provide secure remote access to corporate resources. Under specific conditions, an authorized administrator could bypass security controls to execute unauthorized commands on the underlying operating system. While this requires existing administrative access, it could allow a malicious or compromised administrator to gain full control over the appliance, potentially leading to data theft or network disruption.

Technical details

A code injection vulnerability (CWE-94) exists in the SonicWall SMA1000 Appliance Management Console (AMC). The flaw stems from improper control of code generation, which can be exploited by a remote authenticated attacker with administrative privileges. By sending specially crafted input under specific conditions, the attacker can achieve arbitrary OS command execution on the underlying Linux-based platform. The vulnerability affects firmware versions 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. Exploitation requires valid administrative credentials.

Affected products

  • SonicWall SMA1000 12.4.3-03245 to 12.4.3-03434, 12.5.0-02283 to 12.5.0-02800

Timeline

  • 2026-07-14: disclosed: Initial advisory publication by SonicWall and NVD.

References

Related threats