VULNERABILITY OVERVIEW
A maximum-severity (CVSS 10.0) unauthenticated server-side request forgery (SSRF) in the SMA1000 Appliance Work Place interface allows a remote attacker to open a WebSocket-based tunnel to arbitrary localhost-only services, effectively bypassing network segmentation. Rapid7 MDR observed active zero-day exploitation of internet-facing SMA1000 appliances prior to SonicWall's official disclosure, and SonicWall PSIRT confirmed multiple in-the-wild exploitation cases. Both CVE-2026-15409 and CVE-2026-15410 are frequently chained together to achieve OS-level command execution on compromised appliances; no public PoC has been published but working private exploit tooling is confirmed in use.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
SMA1000 models 6210, 7210, 8200v running firmware 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, 12.5.0-02800CITATIONS
- → https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- → https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/
- → https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/
- → https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog
- → https://www.sophos.com/en-us/blog/sonicwall-sma1000-vulnerabilities-in-active-exploitation