Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: +
2 minutes reading time (383 words)
Featured

Cybersecurity Threat Advisory 30-26: SonicWall SMA1000 exploits

Threat update

SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. 

Technical Detail and Additional Info

What is the threat?

CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability in the SMA1000 Workplace interface that allows an unauthenticated attacker to force the appliance to make outbound requests. This could expose internal services, cloud metadata endpoints, and other resources not directly accessible from the internet.

CVE-2026-15410 is a post-authentication code injection vulnerability in the Management Console that allows an authenticated administrator to execute operating system commands on the device.

An attacker could potentially chain these vulnerabilities, using SSRF to access internal resources and code injection to gain full control of the appliance. 

Why is it noteworthy?

These vulnerabilities are actively exploited and affect remote access infrastructure, making them a high-priority risk. CVE-2026-15409 is unauthenticated and carries a CVSS score of 10.0, while CVE-2026-15410 enables command execution after authentication. Together, they can lead to full device compromise. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. SonicWall states there are no mitigations beyond patching. 

What is the exposure or risk?

Affected systems include SMA1000 models 6210, 7210, and 8200v running the following versions:

  • 12.4.3-03245
  • 12.4.3-03387
  • 12.4.3-03434
  • 12.5.0-02283
  • 12.5.0-02624
  • 12.5.0-02800
SSL-VPN on SonicWall firewalls and SMA 100 Series appliances are not affected. Successful exploitation could allow attackers to access internal resources, execute commands on the appliance, steal credentials, exfiltrate data, move laterally through the environment, or cause service disruption. Risk increases when management interfaces are exposed to the internet, administrative access is broadly granted, or monitoring is limited.

What are the recommendations?

 LBT Technology Group the following actions to secure your network infrastructure:

  • Patch immediately to 12.4.3-03453, 12.5.0-02835, or later.
  • Review SonicWall's indicators of compromise (IOCs), including suspicious /api/login and /api/logout activity, anomalous /wsproxy host parameters, hotfix rollbacks involving path traversal, and unexpected routes in conf.json.
  • Treat any IOC findings as a potential breach.
  • Re-image or re-deploy the appliance if compromise is suspected. Reset all user and administrator passwords and rotate TOTP tokens.
  • Restrict management access to trusted networks or VPNs, enforce MFA, and increase logging and monitoring.

References

 For more in-depth information about the recommendations, please visit the following links:

AI Coding Tools Got Hacked Into Hacking: What It M...
CMMC Level 2 Is on Hold: What Defense Contractors ...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024