Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN765
_____________________________________________________________________


DATE                : 16/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running SMA1000 Series Appliances
               software versions prior to 12.4.3-03453, 12.5.0-02835.
 
=====================================================================

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
_____________________________________________________________________



SonicWall SMA1000 Series Appliances Affected By Multiple
Vulnerabilities

10


Overview

Advisory ID	SNWLID-2026-0008
First Published	2026-07-14
Last Updated	2026-07-14
Workaround	false
Status          Applicable
CVE             CVE-2026-15409, CVE-2026-15410
CWE             CWE-918, CWE-94
CVSS v3         10.0
CVSS Vector	CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Direct Link

	
Summary

1) CVE-2026-15409 - A Server-side request forgery (SSRF)

A Server-side request forgery (SSRF) vulnerability has been
identified in the SMA1000 Appliance Work Place interface. A
remote unauthenticated attacker could potentially cause the
appliance to make requests to unintended location.

CVSS Score: 10.0
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-918: Server-Side Request Forgery (SSRF)


2) CVE-2026-15410 - Post-authentication improper control of
generation of code ('Code Injection')

Post-authentication improper control of generation of code
('Code Injection') vulnerability has been identified in the
SMA1000 Appliance Management Console (AMC) which in specific
conditions could potentially enable a remote authenticated
attacker as administrator to execute arbitrary OS commands.

CVSS Score: 7.2
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-94: Improper Control of Generation of Code ('Code Injection')


IMPORTANT: SonicWall PSIRT has investigated multiple cases
indicating the active exploitation of the vulnerabilities
described in this advisory. Customers are strongly urged to
upgrade to the hotfix release as soon as possible to
remediate these vulnerabilities.


Affected Product(s)
Affected Product                Affected Version(s)

SMA1000 Models - 6210,
7210, 8200v                12.4.3-03245, 12.4.3-03387 and
                           12.4.3-03434 (platform-hotfix)

                           12.5.0-02283, 12.5.0-02624 and
                           12.5.0-02800 (platform-hotfix)


Note: These vulnerabilities do not affect SSL-VPN running
on SonicWall firewalls or the SMA 100 Series product line.

The latest platform-hotfix is available for download on
mysonicwall.com

CPE(s)

Workaround
None.


Fixed Software

Fixed Product                     Fixed Version(s)

SMA1000 Models - 6210,
7210, 8200v                 12.4.3-03453 (platform-hotfix)
                            and higher versions.

                            12.5.0-02835 (platform-hotfix)
                            and higher versions.



Comments

Indicators of Compromise (IOCs)

Customers should review logs for signs including, but not
limited to:

- if in extraweb_access.log are mentioned requests to
/__api__/login or /__api__/logout with http 200 status

- if in extraweb_access.log are mentioned requests to
/wsproxy with suspicious host parameters with 101 http status

- if in ctrl-service.log are mentioned hotfix rollbacks
with path traversal names

- if /var/lib/unit/conf.json contains routes for /__api__/login
or /__api__/logout (these URIs do not exist in legitimate
configuration)


Recommended Actions

Customers are strongly encouraged to:

- Upgrade to the latest hotfix version. (The latest
platform-hotfix is available for download on mysonicwall.com)

- Perform a thorough forensic analysis of the system to
determine if any indicators of compromise (IoCs) are
present.

- If IOCs are present on the system:
          - Re-image (hardware) or re-deploy (virtual)
             appliances.
          - Change user & administrator passwords.
          - Reset TOTP tokens

Credit(s)

Internally discovered and reported by Adam Babis of SonicWall
PSIRT.

Sean Koessel and Steven Adair of Volexity - helped advance
SonicWall's PSIRT investigation, leading to the
identification of an additional IOC.



Revision History
Version
1.0

Date
14-Jul-2026

Description
Initial Release.

---------------------------------------

Version
1.1

Date
14-Jul-2026

Description
Updated Credits section - Updated the Credits section to
acknowledge Sean Koessel and Steven Adair of Volexity for
their contribution to the investigation.

Reference(s)


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




