PublicCVE

CVE-2026-15409

CRITICAL10.0SSRF
CISA KEVRansomwarePublic PoCNewsHigh EPSS

Description

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected products

Exploits & proofs of concept

Updated 44m ago · 8 sources