CVE-2026-15410
HIGH KEVSonicwall SMA1000 - Improper Control of Generation of Code ('Code Injection')
Title source: ruleExploitation Summary
CVE-2026-15410 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 14, 2026. EIP tracks 2 public exploits from researchers including MrRawBit, HORKimhab.
AI-analyzed exploit summary This repository provides a Bash script that scans SonicWall SMA1000 logs for indicators of compromise (IoCs) related to CVE-2026-15410 and CVE-2026-15409. It checks for suspicious patterns in access and control logs but does not exploit the vulnerabilities.
Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Exploits (2)
This repository provides a Bash script that scans SonicWall SMA1000 logs for indicators of compromise (IoCs) related to CVE-2026-15410 and CVE-2026-15409. It checks for suspicious patterns in access and control logs but does not exploit the vulnerabilities.
This repository contains a conceptual Python proof-of-concept for CVE-2026-15410, a command injection vulnerability in SonicWall SMA1000's AMC interface. The exploit attempts to authenticate and inject commands via diagnostic endpoints using common command separators, though it notes the actual vulnerable endpoint is not public.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H