← Back to browse · API

CVE-2026-15410

Severity
HIGH
CVSS
7.2
EPSS
0.76347
Risk score
80.52
CISA KEV
Yes
PoC
Yes
Published
2026-07-14
Modified
2026-08-04
First seen
2026-08-07
Aliases
EUVD-2026-44410, GHSA-PXC4-295P-35QQ
Products
SonicWall:SMA1000 12.4.3-03245 ≤12.4.3-03434, SonicWall:SMA1000 12.5.0-02283 ≤12.5.0-02800, SonicWall:SMA1000 Appliances
Sources
cisa.gov CVE-2026-15410
euvd EUVD-2026-44410
packetstorm 4128973b807d9d44ce941de1|CVE-2026-15410

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

References