Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Published: 2026-07-14
Score: 7.2 High
EPSS: 76.3% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

The SMA1000 Appliance Management Console suffers from a post‑authentication improper control of code generation flaw (CWE‑94) that allows an authenticated administrator to inject and run arbitrary operating‑system commands. Because the code generation process is not properly controlled, an attacker can execute any command that the console’s runtime environment permits, giving them full control of the device’s operating system. This leads to complete compromise of confidentiality, integrity, and availability on the affected appliance.

Affected Systems

The vulnerability exists solely in SonicWall’s SMA1000 appliance, specifically its management console component. Only installations that expose the console over the network are at risk; other SonicWall products are not impacted.

Risk and Exploitability

With a CVSS score of 7.2, the issue is classified as high severity. An EPSS score of 76% indicates a very high likelihood of exploitation, and the vulnerability’s listing in CISA’s KEV catalog confirms that attacks have already been observed. Exploitation requires an authenticated administrator account, making insider activity or compromised credentials the primary attack vectors.

Generated by OpenCVE AI on August 1, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest SonicWall SMA1000 firmware update or patch that removes the code injection flaw.
  • Limit management console access to a dedicated administrative subnet, enforce strict IP‑based filtering, and disable remote console access when it is not required.
  • Use strong, regularly changed administrator passwords and enable multi‑factor authentication for console login whenever the hardware supports it.

Generated by OpenCVE AI on August 1, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title SonicWall SMA1000 Code Injection Allowing Remote Authenticated OS Command Execution

Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title SonicWall SMA1000 Code Injection Allowing Remote Authenticated OS Command Execution

Sat, 25 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Post-Authentication Remote Code Execution in SonicWall SMA1000 Appliance Management Console via Code Injection

Wed, 22 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Post-Authentication Remote Code Execution in SonicWall SMA1000 Appliance Management Console via Code Injection

Fri, 17 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Code Injection Compromise on SonicWall SMA1000

Thu, 16 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Code Injection Compromise on SonicWall SMA1000

Wed, 15 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall sma1000
Vendors & Products Sonicwall
Sonicwall sma1000

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Weaknesses CWE-94
References
Metrics kev

{'dateAdded': '2026-07-14T00:00:00+00:00', 'dueDate': '2026-07-17T00:00:00+00:00'}


Subscriptions

Sonicwall Sma1000
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-04T03:56:15.680Z

Reserved: 2026-07-10T14:12:17.270Z

Link: CVE-2026-15410

cve-icon Vulnrichment

Updated: 2026-07-14T20:10:45.329Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')