SonicWall SMA 1000 Zero-Days: Remote Access Appliances Turned Into Backdoors
- Jul 21
- 3 min read
Two zero-day vulnerabilities in SonicWall's SMA 1000 remote access appliances are being exploited in the wild, and attackers are using the appliances themselves as a route into corporate networks. SonicWall confirmed active exploitation on 14 July. CISA followed within days, adding both flaws to its Known Exploited Vulnerabilities catalogue and giving US federal agencies until 17 July to patch or disconnect the devices.
What Happened
The two flaws are CVE-2026-15409, an unauthenticated server-side request forgery bug rated CVSS 10.0, and CVE-2026-15410, a code injection flaw in the appliance management console. Each is serious on its own. Chained together they are worse: the SSRF lets an unauthenticated attacker reach internal services on the appliance through its WorkPlace web interface, and the second flaw then runs commands as root through a path traversal in the hotfix rollback process. Rapid7's managed detection team spotted the exploitation before SonicWall's advisory went out, and a proof-of-concept for the first flaw is already public.
Why It Matters
SMA 1000 appliances are common in Australian organisations that give staff and contractors remote access to internal systems, and an internet-facing box carrying a CVSS 10.0 flaw is exactly what attackers scan for around the clock. Rapid7 watched intruders harvest credentials, active session databases and time-based one-time password seeds from compromised appliances, then authenticate straight into domain controllers with no VPN tunnel — using workstation names such as 'kali' that no legitimate employee would run. The affected models are the 6210, 7210 and 8200v; SonicWall firewalls and the SMA 100 series are not affected.
Once a perimeter appliance is compromised, it stops being a gateway and becomes the quietest backdoor an attacker could ask for.
What Security Teams Should Do Now
Find every internet-facing SMA 1000 appliance (models 6210, 7210 and 8200v) and confirm the firmware version each one is running.
Upgrade to the fixed platform hotfixes, 12.4.3-03453 or 12.5.0-02835 or later, on an emergency basis. There are no workarounds.
Do not assume patching is enough. Because exploitation began before the advisory, review appliance logs for the published indicators, such as suspicious /wsproxy requests and hotfix-removal calls containing path traversal sequences.
Hunt for lateral movement, particularly domain controller logons sourced from the appliance's internal IP address or from unfamiliar workstation names.
If you find signs of compromise, treat the appliance as fully owned: re-image it, rotate every user and administrator password, and reset TOTP MFA seeds.
Limit exposure of management interfaces and block traffic from hosting providers you have no reason to trust; Rapid7 named ranges belonging to FNS Holdings.
Aurian's Take
Edge devices have become the front door for network intrusions, and this case follows a familiar pattern. Perimeter appliances such as VPNs, remote access gateways and firewalls run complex code, sit directly on the internet, and often stay on older firmware because updating them means downtime. Attackers know this. A single unauthenticated flaw in one of these boxes can hand over an entire internal network, and the appliance's trusted position means an intrusion can go unnoticed for weeks. What stands out about the SMA 1000 attacks is how clean the chain is: reach a local service, run code, escalate to root, and walk away with the keys to the directory.
This is the kind of exposure regular penetration testing is built to find. A good security assessment looks at an organisation the way an attacker does, from the outside in, and internet-facing appliances are the first thing on the list. Testing that maps and probes the perimeter surfaces the forgotten VPN concentrator, the management console that was never meant to face the internet, and the box running firmware two years out of date, well before a real intruder gets there. At Aurian we treat edge infrastructure as a priority in every engagement, because it is consistently where the quickest and quietest path into a network starts. Timing matters too: a clean penetration test in January says little about an appliance that a zero-day exposed in July, which is why perimeter testing needs to be a routine rather than a one-off.
The SMA 1000 flaws will be patched and the news cycle will move on, but the lesson stays put: the edge of your network is where attackers look first, and it deserves that same attention from you. Knowing what an outsider can see and reach is the difference between finding these gaps yourself and reading about them in an advisory.
To find out how Aurian can help your organisation assess its exposure, get in touch.
