HIGH

CVE-2026-15410

Sonicwall Sma6210 Firmware 2026-07-14 CVSS v3.1
CVSS
7.2
KEV

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Summary dbcve.org

A post-authentication code injection vulnerability in the SMA1000 Appliance Management Console (AMC) allows an authenticated administrator to execute arbitrary OS commands through improper control of code generation. The attacker must have valid administrator credentials to exploit this flaw.

Mitigation

Restrict administrative access to the AMC to trusted IP addresses and users, enforce strong password policies, and apply vendor-provided patches when available. Monitor for suspicious administrative activities.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

11.79%
Probability of exploitation in next 30 days
95.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE