A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
| Vendor | Product | Versions |
|---|---|---|
| sonicwall | sma6210_firmware | 12.4.3-03245, 12.5.0-02283 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| sonicwall | sma | cert_advisory | 90% |
| sonicwall | sma7210_firmware | cve_cpe | 95% |
| sonicwall | sma8200v | cve_cpe | 95% |
| sonicwall | sma6210 | cve_cpe | 95% |
| sonicwall | sma7210 | cve_cpe | 95% |
Added patched versions 12.4.3-03453 and 12.5.0-02835, provided detailed technical exploitation chain including CVE-2026-15410 command injection, specific endpoint names (/wsproxy, sysCtrl.execRemoveHotfix), malware component details (Sou5 as reverse proxy, ORANGETAIL webshell functionality), and CouchDB enumeration technique.
Added significant technical details about exploitation including custom malware (KnuckleBall, OrangeTail, Suo5) deployed post-compromise, confirmed exploitation timeline starting June 22, and attributed threat actor UTA0533 activity appears consistent with state-sponsored APT operations.
Added significant technical detail about the pre-authentication /wsproxy bypass mechanism, confirmed active exploitation by UTA0533 threat actor since June 22, 2026, added MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) and T1133 (External Remote Services), and added threat actor and privilege escalation tags.
Updated description with technical details on exploitation and added new affected versions and tags.
Added affected version 12.4.3-03453, updated patch availability to null, and included a new IOC URL.
Updated affected versions to include 12.5.x prior to 12.5.0-02835 and 12.4.3-03453, and marked the vulnerability as actively exploited.
Updated affected versions to include 6210, 7210, and 8200v, marked exploit as available, and noted active exploitation of the vulnerability.
Updated affected versions, marked the vulnerability as actively exploited, added new patch version, and included indicators of compromise (IOCs) and relevant tags.
Updated affected versions and marked the vulnerability as actively exploited.
Initial creation