Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
| Vendor | Product | Versions |
|---|---|---|
| sonicwall | sma6210_firmware | 12.4.3-03245, 12.5.0-02283 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| sonicwall | sma | cert_advisory | 90% |
| sonicwall | sma7210_firmware | cve_cpe | 95% |
| sonicwall | sma8200v | cve_cpe | 95% |
| sonicwall | sma6210 | cve_cpe | 95% |
| sonicwall | sma7210 | cve_cpe | 95% |
Added patched versions (12.4.3-03453, 12.5.0-02835) and significantly expanded description with technical exploitation details including the attack chain, RPC method exploited, and malware payload information.
Added malware artifacts (KnuckleBall, OrangeTail, Suo5) deployed post-exploitation and KEV Catalog tag; confirmed remote unauthenticated attack vector contrary to previous authentication requirement in description.
Added threat actor attribution (UTA0533) and confirmation that CVE-2026-15410 was exploited as a zero-day since June 22, 2026, chained with CVE-2026-15409 for command execution.
Updated description with technical details, added new affected versions, and included new relevant tags.
Updated affected versions to include 12.5.x prior to 12.5.0-02835 and 12.4.3 prior to 12.4.3-03453, and added IOC URL.
Added affected versions 12.5.0-02835 and 12.4.3-03453, marked exploit as available, and added new tags.
Updated patch version to 12.4.3-03453, added new affected versions, and included indicators of compromise.
Updated affected versions to include 6210, 7210, and 8200v, added new patch versions, and marked exploit as available.
Updated severity to CRITICAL and marked the vulnerability as actively exploited.
Updated to indicate that the vulnerability is actively exploited, added new affected versions, and provided specific indicators of compromise.
Updated affected versions, changed severity to CRITICAL, marked as actively exploited, and noted that exploits are available.
Initial creation