ZeroHour
Security Affairspublished ()ingested @securityaffairs

SonicWall warns of active exploitation of two SMA 1000 zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-15409CVE-2026-15410CVE-2025-23006

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-23006
Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances

CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published.

Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections.

9.823% KEV ransomware
  • SonicWall SMA1000 Appliances — Appliance Management Console (AMC) and Central Management Console (CMC)
largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed
CVE-2026-15409
+1 in the same advisory: …15410
Unauthenticated SSRF in SonicWall SMA1000 Appliances

CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available.

Do: Apply SonicWall's SMA1000 firmware update per the vendor's instructions immediately, prioritizing appliances with the Appliance Work Place interface reachable from the internet. Because the flaw is in CISA's KEV with known ransomware use and may be chained with a second SMA1000 zero-day, hunt for signs of compromise (unexpected outbound or internal requests, anomalous VPN sessions, follow-on ransomware activity) and restrict internet exposure of the interface in the interim. Federal and critical-infrastructure operators must comply with CISA BOD 26-04, including cloud-service guidance, or discontinue use if mitigations are unavailable.

10.0
group max
85% KEV ransomware
  • SonicWall SMA1000 Appliances (SMA 6210 firmware)
  • SonicWall SMA1000 Appliances (SMA 7210 firmware)
  • SonicWall SMA1000 Appliances (SMA 8200v)
largeon the order of tens of thousands of internet-exposed appliances (estimate)
Full article528 words · extracted from securityaffairs.com · click to collapse

SonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution.

SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.

The company investigated multiple incidents indicating these vulnerabilities are being actively exploited in the wild.

The first vulnerability, tracked as CVE-2026-15409 (CVSS score of 10.0), is a Server-side request forgery (SSRF) issue that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location.

“A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.” reads the advisory.

The second vulnerability, tracked as CVE-2026-15410 (CVSS score of 7.2), is a post-authentication code injection flaw in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.

“Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.” continues the advisory. “SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.”

The vulnerabilities impact the following software and versions:

Affected ProductAffected Version(s)
SMA1000 Models – 6210, 7210, 8200v 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)

The company addressed the issue in the following versions:

  • 12.4.3-03453 (platform-hotfix) and higher versions.
  • 12.5.0-02835 (platform-hotfix) and higher versions.

Customers should review system logs for indicators of compromise, such as unusual requests to login or logout API endpoints, suspicious WebSocket proxy connections, evidence of hotfix rollbacks using path traversal techniques, or unauthorized API routes in the appliance configuration.

SonicWall strongly recommends upgrading to the latest hotfix, performing a full forensic investigation, and, if compromise is confirmed, re-imaging or redeploying the appliance, resetting all user and administrator passwords, and re-enrolling TOTP tokens.

Sean Koessel and Steven Adair of Volexity helped advance PSIRT investigation, leading to the identification of an additional IOC.

“Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.” concludes the advisory.

In December, SonicWall urged customers to address another SMA1000 Appliance Management Console issue that was exploited as a zero-day in attacks in the wild.

The flaw is a local privilege escalation issue which is due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

“A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).” reads the advisory published by the company. “Please note that SonicWall Firewall products are not affected by this vulnerability.”

The vendor warned customers that the vulnerability was chained with CVE-2025-23006 (CVSS score 9.8) in zero-day attacks to escalate privileges. The vendor has not disclosed details about the attacks that exploited the flaw as a zero-day, nor the attackers’ motivations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SMA 1000)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195364/hacking/sonicwall-warns-of-active-exploitation-of-two-sma-1000-zero-days.html