SonicWall SMA1000 bug can let attackers redirect appliance requests
A flaw in SonicWall SMA1000 appliances lets attackers trick the device into sending requests to their own servers instead of the intended ones. This can let them steal data or redirect users to fake sites.
- Severity
- CriticalCVSS 3.1 · 10.0
- Fix
- Not confirmedLast checked on Sep 4, 2026
- Affected versions
- 12.4.3-03245 through 12.4.3-03434; 12.5.0-02283 through 12.5.0-02800
- Weakness
- CWE-918Server-Side Request Forgery (SSRF)
- Exploit likelihood
- 85% in 30 daysEPSS, higher than 100% of known flaws
- Affects
- SMA1000
- Exploited
- Yes, in the wildListed by CISA, used in ransomware
- Added to CISA list
- Jul 14, 2026
- Federal fix deadline
- Jul 17, 2026
How it works
An attacker sends a specially crafted request to the SMA1000's web interface that forces it to send its own requests to a server controlled by the attacker instead of the real destination.
What to do
Check whether the installed SonicWall SMA1000 version is older than the fixed version in the vendor advisory or current release.
Update to the latest firmware version from SonicWall's support site. Restart the appliance after updating to apply changes.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 appliances (CVE-2026-15409) allows attackers to manipulate the appliance's internal network requests. By sending specially crafted inputs, an attacker could force the device to send requests to arbitrary internal or external servers, potentially exposing sensitive backend systems or redirecting traffic to malicious endpoints. This could enable further attacks, such as data exfiltration or lateral movement within a network.
The flaw affects SonicWall SMA1000 appliances and was added to CISA's KEV Catalog due to active exploitation. No fixed version was disclosed in the source.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- psirt.global.sonicwall.com · SNWLID-2026-0008 Vendor Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource