Vulnerabilities
Vulnerable Software
Sonicwall:  Security Vulnerabilities
CVE-2026-15409
Known exploited
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
CVSS Score
10.0
EPSS Score
0.784
Published
2026-07-14
CVE-2026-15410
Known exploited
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVSS Score
7.2
EPSS Score
0.763
Published
2026-07-14
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
CVSS Score
8.0
EPSS Score
0.004
Published
2026-04-29
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
CVSS Score
6.8
EPSS Score
0.004
Published
2026-04-29
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
CVSS Score
4.9
EPSS Score
0.005
Published
2026-04-29
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
CVSS Score
7.2
EPSS Score
0.004
Published
2026-04-09
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
CVSS Score
7.2
EPSS Score
0.006
Published
2026-04-09
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
CVSS Score
7.2
EPSS Score
0.004
Published
2026-04-09
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
CVSS Score
6.6
EPSS Score
0.006
Published
2026-04-09
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.
CVSS Score
2.7
EPSS Score
0.004
Published
2026-03-31


Contact Us

Shodan ® - All rights reserved