Two SonicWall SMA1000 flaws were exploited as zero-days for weeks before public disclosure, allowing attackers to compromise vulnerable VPN appliances and install custom malware.
The vulnerabilities affect SonicWall SMA1000 6210, 7210, and 8200v appliances. SonicWall issued patches last week and confirmed that threat actors had actively exploited the flaws in attacks.
Incident response firm Volexity, which assisted with the investigation, said the campaign began as early as 22 June. It tracks the previously unknown threat actor behind the activity as UTA0533.
Two SonicWall SMA1000 Flaws Were Chained Together
The attack relied on two vulnerabilities:
- CVE-2026-15409, a critical server-side request forgery vulnerability.
- CVE-2026-15410, a high-severity command injection vulnerability.
Attackers first exploited CVE-2026-15409 through the SMA1000 appliance’s /wsproxy endpoint. This allowed them to create unauthenticated WebSocket tunnels to internal services that should not have been accessible externally.
The exposed services included CouchDB and the appliance management interface.
Volexity found that the attackers queried CouchDB to obtain the appliance’s product_uuid. That value was required for the next stage of the attack, although researchers could not confirm exactly how the group accessed the database.
The attackers then used the product_uuid to exploit CVE-2026-15410 through the Appliance Management Console’s sysCtrl.execRemoveHotfix RPC method. This gave them the ability to execute commands as root and take full control of the device.
Attackers Deployed KNUCKLEBALL and Java Malware
After gaining root access, UTA0533 installed a custom malware dropper called KNUCKLEBALL. It was deployed under the filename deploy_new.py.
KNUCKLEBALL then installed two Java-based malware families designed for SonicWall SMA1000 appliances:
- Sou5, stored as
agent_wp8.jar - ORANGETAIL, stored as
agent_wp9.jar
Sou5 works as a reverse proxy. It enables attackers to tunnel traffic through the compromised appliance and maintain covert access to internal resources.
ORANGETAIL is a Java webshell that allows attackers to send encrypted Java payloads to the appliance and execute them dynamically during HTTP sessions.
The attackers also modified the device’s nginx configuration to expose the ORANGETAIL webshell remotely. In addition, they installed a privilege-escalation tool called ROOTRUN to run commands as root.
Patches Are Available for Affected Appliances
SonicWall released fixes for the SonicWall SMA1000 flaws in versions 12.4.3-03453 and 12.5.0-02835.
Organisations using affected SMA1000 appliances should install the updates as soon as possible. The flaws were already under active exploitation before patches became available, and successful attacks can give threat actors full administrative control of a VPN appliance.
Although Volexity described the campaign as technically sophisticated, it found limited evidence that UTA0533 successfully moved deeper into affected internal networks.


0 responses to “SonicWall SMA1000 Flaws Exploited as Zero-Days to Deploy Malware”