Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
References
| Link | Resource |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410 | US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
15 Jul 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03434:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:12.5.0-02800:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02283:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02283:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03387:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03245:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:12.4.3-03245:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02624:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6210_firmware:12.5.0-02800:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02624:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:12.5.0-02624:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma7210_firmware:12.5.0-02800:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:12.5.0-02283:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03387:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma7210_firmware:12.4.3-03245:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:12.4.3-03434:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:12.4.3-03387:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6210_firmware:12.4.3-03434:*:*:*:*:*:*:* |
|
| First Time |
Sonicwall sma7210 Firmware
Sonicwall Sonicwall sma6210 Sonicwall sma6210 Firmware Sonicwall sma7210 Sonicwall sma8200v |
|
| References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 - Vendor Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410 - US Government Resource |
14 Jul 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| References |
|
14 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 20:16
Updated : 2026-07-16 05:16
NVD link : CVE-2026-15410
Mitre link : CVE-2026-15410
CVE.ORG link : CVE-2026-15410
JSON object : View
Products Affected
sonicwall
- sma8200v
- sma7210_firmware
- sma6210_firmware
- sma6210
- sma7210
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
