Skip to content

Critical Gaps in SonicWall SMA1000 – SSRF and Code Injection Actively Exploited

At a glance: Two critical vulnerabilities in SonicWall SMA1000 (CVE-2026-15409 SSRF with CVSS 10.0, CVE-2026-15410 Code Injection with CVSS 7.2) are being actively exploited in production; hotfixes available, forensic investigation required.

SonicWall warns of two critical vulnerabilities in the SMA1000 Series (models 6210, 7210, 8200v) that are already being actively exploited. The vulnerabilities enable unauthenticated remote attacks and code execution on the management console.

Vulnerabilities and Impact

CVE-2026-15409 is a Server-Side Request Forgery (SSRF) in the Workplace interface of the SMA1000, which enables an unauthenticated attacker to cause the appliance to send requests on the server side to internal endpoints that are normally unreachable. The CVSS Base Score is 10.0. CVE-2026-15410 affects the Appliance Management Console (AMC) and allows an authenticated administrator with improper code generation to execute arbitrary operating system commands (CVSS Base Score 7.2).

Affected Versions

The vulnerabilities affect models 6210, 7210, and 8200v in versions 12.4.3-03245 through 12.4.3-03434 and 12.5.0-02283 through 12.5.0-02800. SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected. The vendor confirms active exploitation in practice.

Updates and Forensics

SonicWall provides platform hotfixes: version 12.4.3-03453 and later as well as 12.5.0-02835 and later. No workaround exists. Patches are available via mysonicwall.com. When active exploitation is identified, systems should be examined for Indicators of Compromise: entries in extraweb_access.log with requests to /__api__/login or /__api__/logout (HTTP 200), requests to /wsproxy with suspicious host parameters (HTTP 101), hotfix rollbacks with path-traversal names in ctrl-service.log, and suspicious routes in /var/lib/unit/conf.json.

Incident Response

If IOCs are identified, SonicWall recommends immediate reimaging of affected appliances (hardware: re-image, virtual: re-deploy), changing all user and administrator passwords, and resetting TOTP tokens. CERT.at emphasizes the need for up-to-date software and automated updates with regular restarts.


Source: www.cert.at · Published 15 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: