CVE-2026-15410
Description
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Summary dbcve.org
A post-authentication code injection vulnerability in the SMA1000 Appliance Management Console (AMC) allows an authenticated administrator to execute arbitrary OS commands through improper control of code generation. The attacker must have valid administrator credentials to exploit this flaw.
Mitigation
Restrict administrative access to the AMC to trusted IP addresses and users, enforce strong password policies, and apply vendor-provided patches when available. Monitor for suspicious administrative activities.