본문으로 이동
ONEPRESS

TECHNOLOGY

SonicWall SMA 1000 flaws are being exploited: patch, then check for compromise

Technology briefing
Briefings by language
An enterprise administrator checks a remote-access security appliance and logs in a server room
A ONEPRESS technology and public-safety image focused on verifying appliance versions and logs in a real operations setting.
  • Checked: 2026-07-15 20:11 KST
  • Basis: SonicWall product notice and PSIRT guidance dated July 14, cross-checked against CISA KEV

What changed

SonicWall confirmed on July 14 that CVE-2026-15409 and CVE-2026-15410 affecting the SMA 1000 Series are being exploited in the wild. The first is an SSRF issue rated CVSS 10.0. The second is code injection that, under specific conditions, can let an authenticated administrator execute operating-system commands and is rated 7.2. CISA added both to its Known Exploited Vulnerabilities catalog.

This is more than a routine update notice. SonicWall tells affected operators to install the latest hotfix and perform a forensic review for indicators of compromise. If indicators are found, hardware appliances should be re-imaged, virtual appliances redeployed, user and administrator passwords changed, and TOTP tokens reset.

Installed is not the same as cleared. Because this is an actively exploited edge device, version verification, evidence preservation, log and configuration review, and conditional rebuilds belong in one incident-minded task.

Affected products and builds

  • Products: SMA 1000 models 6210, 7210 and 8200v, plus CMS on all hypervisors.
  • Affected 12.4.3 builds: 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434.
  • Affected 12.5.0 builds: 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800.
  • Fixed baseline: 12.4.3-03453 or later, or 12.5.0-02835 or later. Check the complete hotfix build, not only “12.4.3” or “12.5.0.”
  • Scope: the notice concerns SMA 1000. It does not say every SonicWall firewall or the separate SMA 100 family is affected by these same flaws.

Seven steps for today

  1. Fix the inventory: list each physical and virtual SMA 1000 and CMS instance with model, full build, public exposure, owner, provider and backup location.
  2. Read the full hotfix version: in AMC use System Configuration → Maintenance and the hotfixes link; in CMC use Maintain → Maintain Server and the hotfixes link. Keep a screenshot or change record.
  3. Apply the latest hotfix: obtain the correct current release from MySonicWall after confirming change approval, service continuity, backup and recovery access. Prefer the vendor’s latest hotfix over merely reaching the minimum fixed build.
  4. Preserve evidence first: before updating or restarting, retain extraweb_access.log, ctrl-service.log, audit and authentication logs, the current configuration, and timestamps or hashes. Check whether remote logging missed the relevant period.
  5. Review official indicators: look for HTTP 200 requests to /_api_/login or /__api__/logout; /wsproxy requests with suspicious host parameters and HTTP 101; “hotfix removal” entries with traversal names in ctrl-service.log; and /__api__/login or /__api__/logout routes in /var/lib/unit/conf.json.
  6. Escalate if indicators exist: re-image hardware or redeploy virtual appliances from a trusted source. Change user and administrator passwords, reset TOTP tokens, and inspect downstream systems for unusual sessions, logins and privilege changes.
  7. Test the real path: verify remote login, MFA/TOTP, approved application access, logout, administrator access and log forwarding. Record build, completion time, owner, IoC result, rebuild status and credential action per device.

Why backup age matters

  • If indicators are present, SonicWall says configuration backups should predate installation of the December hotfix builds 12.4.3-03245 and 12.5.0-02283.
  • Where no older backup exists, audit the configuration closely for tampering. Restoring a potentially altered configuration can undo the value of a clean rebuild.
  • Re-imaging is a continuity event: confirm HA order, identity integration, certificates, routes, policy, licensing, console access and recovery owners before starting.

Questions for users and leaders

  • Users: check the official help desk for remote-access changes. Do not follow an unsolicited password or MFA re-enrollment link; navigate to the known portal directly.
  • Leaders: ask for affected-device count, full builds, hotfix completion, IoC results, rebuild scope and password/TOTP reset scope—not only whether automatic updates are enabled.
  • Service providers: separate device and tenant scope per customer, preserve evidence, and provide version and review results. Shared administrator credentials or TOTP practices widen the investigation.

Read the alert without overstatement

  • Active exploitation does not prove every SMA 1000 is compromised; device-specific log and configuration evidence is required.
  • A hotfix also does not prove the device was clean before installation. That is why the vendor explicitly calls for forensic analysis.
  • CISA’s July 17 due date binds U.S. federal civilian agencies, not every organization worldwide. It is still a strong prioritization signal for an actively exploited edge appliance.
  • The official notice does not identify victims or an attacker. Do not invent a breach count or attribution.

Primary sources

Bottom line: If you operate SMA 1000, confirm the model and full build today, install the latest hotfix, preserve evidence and review the official indicators. If indicators exist, expand to a rebuild plus password and TOTP resets.