CRITICAL
CVE-2026-15409
CVSS
10
KEV
Description
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Summary dbcve.org
A Server-side request forgery (SSRF) vulnerability exists in the SMA1000 Appliance Work Place interface, allowing remote unauthenticated attackers to cause the appliance to make HTTP requests to arbitrary locations, potentially reaching internal systems or exfiltrating data.
Mitigation
Apply vendor patches for SMA1000 when available; restrict network access to the Work Place interface using firewall rules or ACLs to limit exposure to untrusted networks.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
84.54%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.