FAIL › dossier
SMA1000 Appliances
PRODUCT· dossier confidence 50%
SMA1000 Appliances have experienced critical security vulnerabilities, highlighting potential weaknesses in their security posture.
PROFILE
CategorySecurity ApplianceWhat they doSMA1000 Appliances are designed for small to medium-sized businesses, providing network security and management solutions.
SECURITY POSTURE
The company has faced multiple critical and high-severity vulnerabilities in their SMA1000 appliances, indicating a potential lack of robust security practices.
Notable failures
- CVE-2025-23006: Remote, unauthenticated execution of arbitrary OS commands
- CVE-2026-15410: Code injection allowing remote admin to execute arbitrary commands
- CVE-2026-15409: Unauthenticated server-side request forgery attacks
Patterns: Repeated deserialization vulnerabilities; Exposure to code injection and server-side request forgery attacks
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-01-24 | CVE-2025-23006 | critical | SonicWall SMA1000 appliances suffered a deserialization vulnerability allowing remote, unauthenticated attackers to execute arbitrary OS commands. |
| 2026-07-14 | CVE-2026-15410 | high | SonicWall SMA1000 appliances exposed to code injection, allowing remote admin to execute arbitrary commands. |
| 2026-07-14 | CVE-2026-15409 | high | SonicWall SMA1000 appliances exposed to unauthenticated server-side request forgery attacks |
Open questions: Why have these vulnerabilities persisted despite the company's presence in the security industry? · What measures have been taken to prevent future security breaches?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:44:53.829922+00:00