قاعدة الثغرات (CVE)
CVE-2026-15410
حقن شفرة لمسؤول مصادَق في SonicWall SMA1000
عاليةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد
في شروط محددة، يستطيع مهاجم عن بُعد مصادَق عليه كمسؤول تنفيذ أوامر نظام عشوائية على الجهاز. تُسلسل مع CVE-2026-15409. مرتبطة ببرامج فدية.
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| SMA1000 Appliances | — | — |
التغطية على سيبرانا
—