Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Published: 2026-07-14
Score: 7.2 High
EPSS: 11.8% Moderate
KEV: Yes
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The SMA1000 Appliance Management Console contains a post‑authentication code injection flaw (CWE‑94). When an attacker has authenticated as an administrator, the flaw permits arbitrary operating‑system command execution through the console interface. This capability can lead to full compromise of the device’s confidentiality, integrity and availability. The CVSS score of 7.2 reflects the high level of risk associated with this functionality.

Affected Systems

The vulnerability applies to SonicWall SMA1000 devices, specifically the management console component. Because the CNA data does not list specific firmware revisions, and the CPE entries reference various firmware versions of other models, the only definitive scope covered by the CVE is any SMA1000 appliance whose console is accessible over a network. All deployed SMA1000 units with exposed console services should be considered potentially vulnerable until a vendor fix is applied. This inference is made because the official description explicitly mentions the SMA1000 AMC and no version constraints are provided.

Risk and Exploitability

With an EPSS score of 12%, the probability of exploitation is moderately high, and the vulnerability is already listed in the CISA KEV catalog, indicating that attacks have been observed. The attack vector requires an authenticated administrator session, so compromised credentials or insider threat is the primary path. The combination of a 7.2 CVSS score, verified exploitation, and active attacks warrants immediate remediation.

Generated by OpenCVE AI on August 24, 2026 at 16:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any firmware or software update released by SonicWall that addresses the code injection flaw.
  • If an update is not yet available, restrict console access to a dedicated administrative subnet or VPN, and disable remote console services when they are not needed.
  • Use strong, regularly rotated administrator passwords and enable multi‑factor authentication for console logins where supported.

Generated by OpenCVE AI on August 24, 2026 at 16:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Post‑authentication code injection vulnerability in SonicWall SMA1000 management console

Tue, 04 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Post‑authentication code injection vulnerability in SonicWall SMA1000 management console

Sat, 01 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title SonicWall SMA1000 Code Injection Allowing Remote Authenticated OS Command Execution

Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title SonicWall SMA1000 Code Injection Allowing Remote Authenticated OS Command Execution

Sat, 25 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Post-Authentication Remote Code Execution in SonicWall SMA1000 Appliance Management Console via Code Injection

Wed, 22 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Post-Authentication Remote Code Execution in SonicWall SMA1000 Appliance Management Console via Code Injection

Fri, 17 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Code Injection Compromise on SonicWall SMA1000

Thu, 16 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Code Injection Compromise on SonicWall SMA1000

Wed, 15 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall sma1000
Vendors & Products Sonicwall
Sonicwall sma1000

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Weaknesses CWE-94
References
Metrics kev

{'dateAdded': '2026-07-14T00:00:00+00:00', 'dueDate': '2026-07-17T00:00:00+00:00'}


Subscriptions

Sonicwall Sma1000 Sma6210 Sma6210 Firmware Sma7210 Sma7210 Firmware Sma8200v
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-04T03:56:15.680Z

Reserved: 2026-07-10T14:12:17.270Z

Link: CVE-2026-15410

cve-icon Vulnrichment

Updated: 2026-07-14T20:10:45.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-14T20:16:56.903

Modified: 2026-07-16T05:16:18.470

Link: CVE-2026-15410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T17:00:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')