SonicWall SMA1000 Series Hit by Actively Exploited Zero-Day Vulnerabilities
SonicWall recently disclosed two critical vulnerabilities in its SMA1000 Series remote access appliances, one of which was already under active exploitation before the advisory was published. The flaws CVE-2026-15409 (a server-side request forgery bug with a CVSS score of 10.0) and CVE-2026-15410 (a high-severity local privilege escalation flaw) have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, confirming real-world attacks.
The exploit chain begins with the /wsproxy websocket proxy feature in SonicWall’s WorkPlace application, which attackers manipulate to redirect traffic to internal services. By targeting an Erlang process on port 1050 which uses a hardcoded authentication cookie threat actors achieve unauthenticated remote code execution (RCE). From there, they escalate privileges to root access by exploiting a path traversal flaw in the remove_hotfix workflow, allowing arbitrary script execution.
Affected models include SMA1000 Series 6210, 7210, and 8200v running firmware versions 12.4.3-03434 and 12.5.0-02800. SonicWall firewalls and the SMA 100 Series are not impacted.
Attacker Activity & Impact
Rapid7 researchers observed threat actors leveraging compromised appliances as stealthy entry points into corporate networks. Post-exploitation, attackers harvested credentials, session data, and TOTP MFA seeds, then pivoted into Active Directory environments. Unusual login patterns including authentications from non-corporate devices (e.g., "kali") originating from the appliance itself served as key indicators of compromise.
Mitigation & Indicators of Compromise (IOCs)
SonicWall has released patches (12.4.3-03453 or 12.5.0-02835) to address the flaws, with no workarounds available. Organizations are advised to assume compromise if suspicious activity is detected, including:
- Unusual /wsproxy requests
- Abnormal remove_hotfix calls
- Unexpected NTLM logons from the appliance’s internal IP
Public proof-of-concept exploits for CVE-2026-15409 are already circulating, and a Metasploit module is reportedly in development, increasing the likelihood of widespread attacks.
Attacker Infrastructure
Observed malicious activity has been linked to the following IP ranges:
- 45.131.194.0/24
- 45.146.54.0/24
- 63.135.161.0/24
- 173.239.211.0/24
- Specific IPs: 193.37.32[.]179, 193.37.32[.]214, 216.73.163[.]151, 216.73.163[.]158
Source: https://cybersecuritynews.com/sonicwall-sma1000-0-day-vulnerability-2/
SonicWall cybersecurity rating report: https://www.rankiteo.com/company/sonicwall
"id": "SON1784219373",
"linkid": "sonicwall",
"type": "Vulnerability",
"date": "1/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'SonicWall',
'type': 'Technology Vendor'}],
'attack_vector': 'Exploitation of /wsproxy websocket proxy feature and '
'hardcoded authentication cookie in Erlang process',
'data_breach': {'personally_identifiable_information': 'Yes (credentials, MFA '
'seeds)',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Credentials',
'Session data',
'TOTP MFA seeds']},
'description': 'SonicWall recently disclosed two critical vulnerabilities in '
'its SMA1000 Series remote access appliances, one of which was '
'already under active exploitation before the advisory was '
'published. The flaws CVE-2026-15409 (a server-side request '
'forgery bug with a CVSS score of 10.0) and CVE-2026-15410 (a '
'high-severity local privilege escalation flaw) have been '
'added to CISA’s Known Exploited Vulnerabilities (KEV) '
'catalog, confirming real-world attacks. The exploit chain '
'begins with the /wsproxy websocket proxy feature in '
'SonicWall’s WorkPlace application, which attackers manipulate '
'to redirect traffic to internal services. By targeting an '
'Erlang process on port 1050 which uses a hardcoded '
'authentication cookie, threat actors achieve unauthenticated '
'remote code execution (RCE). From there, they escalate '
'privileges to root access by exploiting a path traversal flaw '
'in the remove_hotfix workflow, allowing arbitrary script '
'execution.',
'impact': {'data_compromised': ['Credentials',
'Session data',
'TOTP MFA seeds'],
'identity_theft_risk': 'High (due to harvested credentials and MFA '
'seeds)',
'operational_impact': 'Compromised appliances used as stealthy '
'entry points into corporate networks; '
'pivoting into Active Directory environments',
'systems_affected': 'SMA1000 Series 6210, 7210, and 8200v running '
'firmware versions 12.4.3-03434 and '
'12.5.0-02800'},
'initial_access_broker': {'entry_point': 'Exploitation of /wsproxy websocket '
'proxy feature',
'high_value_targets': 'Active Directory '
'environments'},
'post_incident_analysis': {'corrective_actions': ['Patch deployment '
'(12.4.3-03453 or '
'12.5.0-02835)',
'Enhanced monitoring for '
'IOCs',
'Assume compromise if '
'suspicious activity is '
'detected'],
'root_causes': ['Zero-day vulnerabilities '
'(CVE-2026-15409, CVE-2026-15410)',
'Hardcoded authentication cookie '
'in Erlang process',
'Path traversal flaw in '
'remove_hotfix workflow']},
'recommendations': 'Assume compromise if suspicious activity is detected; '
'apply patches immediately; monitor for IOCs; restrict '
'access to internal services from the appliance',
'references': [{'source': 'SonicWall Advisory'},
{'source': 'Rapid7 Research'},
{'source': 'CISA KEV Catalog'}],
'regulatory_compliance': {'regulatory_notifications': 'CISA’s Known Exploited '
'Vulnerabilities (KEV) '
'catalog'},
'response': {'enhanced_monitoring': 'Recommended to monitor for unusual '
'/wsproxy requests, abnormal '
'remove_hotfix calls, and unexpected NTLM '
'logons from the appliance’s internal IP',
'remediation_measures': 'Patches released (12.4.3-03453 or '
'12.5.0-02835); no workarounds available',
'third_party_assistance': 'Rapid7 researchers'},
'title': 'SonicWall SMA1000 Series Hit by Actively Exploited Zero-Day '
'Vulnerabilities',
'type': ['Zero-Day Exploitation',
'Remote Code Execution',
'Privilege Escalation'],
'vulnerability_exploited': ['CVE-2026-15409', 'CVE-2026-15410']}