📦

sma8200v

Vendor: sonicwall

Actively Exploited 4 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 2 Remote Access
Total CVEs 12 Total Indexed
Avg. EPSS 3.76% Exploit Prob.
Latest CVE CVE-2026-15410 Jul 14

Security Vulnerability Index

Page 1 / 2
7.2 CVSS
CVE-2026-15410
RCE Exploit Found

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

EPSS: 1.49%
10.0 CVSS
CVE-2026-15409
Exploit Found

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

EPSS: 1.27%
7.2 CVSS

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

EPSS: 0.42%
6.6 CVSS

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.

EPSS: 0.60%
7.2 CVSS

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.

EPSS: 0.36%
7.2 CVSS
CVE-2026-4112
Exploit Found

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.

EPSS: 0.61%
6.6 CVSS

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

EPSS: 1.94%
9.8 CVSS

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

EPSS: 23.43%