Cybersecurity Threat Advisory 30-26: SonicWall SMA1000 exploits
Threat update
SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds.
Technical Detail and Additional Info
What is the threat?
CVE-2026-15410 is a post-authentication code injection vulnerability in the Management Console that allows an authenticated administrator to execute operating system commands on the device.
An attacker could potentially chain these vulnerabilities, using SSRF to access internal resources and code injection to gain full control of the appliance.
Why is it noteworthy?
These vulnerabilities are actively exploited and affect remote access infrastructure, making them a high-priority risk. CVE-2026-15409 is unauthenticated and carries a CVSS score of 10.0, while CVE-2026-15410 enables command execution after authentication. Together, they can lead to full device compromise. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. SonicWall states there are no mitigations beyond patching.
What is the exposure or risk?
Affected systems include SMA1000 models 6210, 7210, and 8200v running the following versions:
- 12.4.3-03245
- 12.4.3-03387
- 12.4.3-03434
- 12.5.0-02283
- 12.5.0-02624
- 12.5.0-02800
What are the recommendations?
LBT Technology Group the following actions to secure your network infrastructure:
- Patch immediately to 12.4.3-03453, 12.5.0-02835, or later.
- Review SonicWall's indicators of compromise (IOCs), including suspicious
/api/loginand/api/logoutactivity, anomalous/wsproxyhost parameters, hotfix rollbacks involving path traversal, and unexpected routes inconf.json. - Treat any IOC findings as a potential breach.
- Re-image or re-deploy the appliance if compromise is suspected. Reset all user and administrator passwords and rotate TOTP tokens.
- Restrict management access to trusted networks or VPNs, enforce MFA, and increase logging and monitoring.
References
For more in-depth information about the recommendations, please visit the following links:
