Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
References
| Link | Resource |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410 | US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-14 20:16
Updated : 2026-07-16 05:16
NVD link : CVE-2026-15410
Mitre link : CVE-2026-15410
CVE.ORG link : CVE-2026-15410
JSON object : View
Products Affected
sonicwall
- sma8200v
- sma7210_firmware
- sma6210_firmware
- sma7210
- sma6210
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
