Impact
A post‑authentication OS Command Injection flaw exists in the SMA1000 Appliance Management Console. An attacker who has administrator credentials can submit unvalidated data that the console incorporates into an operating system command, allowing execution of arbitrary commands. This can lead to full compromise of the appliance.
Affected Systems
The affected product is the SonicWall SMA1000 Appliance Management Console. No specific firmware or software version is documented, so all releases that include the console may be affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score of 9% shows a non‑negligible exploitation probability. The vulnerability is listed in the CISA KEV catalog. Although the attack vector is remote, an attacker must first authenticate as an administrator. Once authenticated, the attacker can run arbitrary OS commands, potentially gaining complete control of the device.
OpenCVE Enrichment