CVE-2026-15410
Vulnerability Summary
Timeline
Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVSS Metrics
- v3.1•HIGH•Score: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 76.35%• Percentile: 99%
Techniques & Countermeasures
- CWE-94•Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Affected Systems
- sonicwall•sma1000_firmware
≥ 12.4.3-03245, ≤ 12.4.3-03434 | ≥ 12.5.0-02283, ≤ 12.5.0-02800
- sonicwall•sma6210_firmware
12.4.3-03245 | 12.4.3-03387 | 12.4.3-03434 | 12.5.0-02283 | 12.5.0-02624 | 12.5.0-02800
- sonicwall•sma7210_firmware
12.4.3-03245 | 12.4.3-03387 | 12.4.3-03434 | 12.5.0-02283 | 12.5.0-02624 | 12.5.0-02800
- sonicwall•sma8200v
12.4.3-03245 | 12.4.3-03387 | 12.4.3-03434 | 12.5.0-02283 | 12.5.0-02624 | 12.5.0-02800