CVE-2026-15410

HIGH KEV

Sonicwall SMA1000 - Improper Control of Generation of Code ('Code Injection')

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2026-15410 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 14, 2026. EIP tracks 2 public exploits from researchers including MrRawBit, HORKimhab.

AI-analyzed exploit summary This repository provides a Bash script that scans SonicWall SMA1000 logs for indicators of compromise (IoCs) related to CVE-2026-15410 and CVE-2026-15409. It checks for suspicious patterns in access and control logs but does not exploit the vulnerabilities.

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Exploits (2)

github SCANNER
by MrRawBit · shellpoc
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

This repository provides a Bash script that scans SonicWall SMA1000 logs for indicators of compromise (IoCs) related to CVE-2026-15410 and CVE-2026-15409. It checks for suspicious patterns in access and control logs but does not exploit the vulnerabilities.

Classification
Scanner 98%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: SonicWall SMA 1000 Series (SMA 6210, SMA 7210, SMA 8200v)
No auth needed
Prerequisites: Root access to the SMA1000 appliance or its log files · Logs must be present in /var/log/aventail/
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →
github WORKING POC
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-15410

This repository contains a conceptual Python proof-of-concept for CVE-2026-15410, a command injection vulnerability in SonicWall SMA1000's AMC interface. The exploit attempts to authenticate and inject commands via diagnostic endpoints using common command separators, though it notes the actual vulnerable endpoint is not public.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: SonicWall SMA1000 (specific version not specified)
Auth required
Prerequisites: Valid administrator credentials for SonicWall SMA1000 · Network access to the target device · Knowledge of the actual vulnerable endpoint (not provided in the PoC)
mistral-large-3 · analyzed Jul 15, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.2
EPSS 0.7635
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-07-14
VulnCheck KEV 2026-07-14
ENISA EUVD EUVD-2026-44410
CWE
CWE-94
Status published
Products (20)
SonicWall/SMA1000 12.4.3-03245 - 12.4.3-03434
SonicWall/SMA1000 12.5.0-02283 - 12.5.0-02800
sonicwall/sma6210_firmware 12.4.3-03245
sonicwall/sma6210_firmware 12.4.3-03387
sonicwall/sma6210_firmware 12.4.3-03434
sonicwall/sma6210_firmware 12.5.0-02283
sonicwall/sma6210_firmware 12.5.0-02624
sonicwall/sma6210_firmware 12.5.0-02800
sonicwall/sma7210_firmware 12.4.3-03245
sonicwall/sma7210_firmware 12.4.3-03387
... and 10 more
Published Jul 14, 2026
KEV Added Jul 14, 2026
Tracked Since Jul 15, 2026