Skip to content
COOEY

FAIL › dossier

SMA1000 Appliances

PRODUCT

· dossier confidence 50%

SMA1000 Appliances have experienced critical security vulnerabilities, highlighting potential weaknesses in their security posture.

PROFILE
CategorySecurity ApplianceWhat they doSMA1000 Appliances are designed for small to medium-sized businesses, providing network security and management solutions.
SECURITY POSTURE

The company has faced multiple critical and high-severity vulnerabilities in their SMA1000 appliances, indicating a potential lack of robust security practices.

Notable failures
  • CVE-2025-23006: Remote, unauthenticated execution of arbitrary OS commands
  • CVE-2026-15410: Code injection allowing remote admin to execute arbitrary commands
  • CVE-2026-15409: Unauthenticated server-side request forgery attacks
Patterns: Repeated deserialization vulnerabilities; Exposure to code injection and server-side request forgery attacks
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2025-01-24 CVE-2025-23006 critical SonicWall SMA1000 appliances suffered a deserialization vulnerability allowing remote, unauthenticated attackers to execute arbitrary OS commands.
2026-07-14 CVE-2026-15410 high SonicWall SMA1000 appliances exposed to code injection, allowing remote admin to execute arbitrary commands.
2026-07-14 CVE-2026-15409 high SonicWall SMA1000 appliances exposed to unauthenticated server-side request forgery attacks
Open questions: Why have these vulnerabilities persisted despite the company's presence in the security industry? · What measures have been taken to prevent future security breaches?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:44:53.829922+00:00