SonicWall SMA1000 appliances let admins run commands
A flaw in SonicWall SMA1000 appliances lets attackers with admin access run commands on the device. This can let them take full control of the network security tool.
- Severity
- HighCVSS 3.1 · 7.2
- Fix
- Not confirmedLast checked on Sep 4, 2026
- Affected versions
- 12.4.3-03245 through 12.4.3-03434; 12.5.0-02283 through 12.5.0-02800
- Weakness
- CWE-94Code Injection
- Exploit likelihood
- 12% in 30 daysEPSS, higher than 96% of known flaws
- Affects
- SMA1000
- Exploited
- Yes, in the wildListed by CISA, used in ransomware
- Added to CISA list
- Jul 14, 2026
- Federal fix deadline
- Jul 17, 2026
How it works
An attacker with admin access sends a specially built request to the SMA1000's command-handling feature, tricking it into running commands on the device's operating system.
What to do
Check whether the installed SonicWall SMA1000 version is older than the fixed version in the vendor advisory or current release.
Update to the latest firmware version from SonicWall's support site, then verify the new version is installed.
Technical details
CVE-2026-15410 is a code injection flaw in SonicWall SMA1000 appliances. An authenticated administrator can, under specific conditions, cause the device to execute arbitrary OS commands, effectively escalating admin-panel access into full command execution on the underlying appliance. CISA added it to the Known Exploited Vulnerabilities catalog, indicating it has been used in real attacks. No further technical detail on the exact injection point or affected firmware range was available in the sources reviewed.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required High Attacker needs admin-level access
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- psirt.global.sonicwall.com · SNWLID-2026-0008 Vendor Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource