Overview
- Security investigators found a coordinated campaign that began at least on June 22 that used two previously unknown flaws to compromise SMA1000 appliances before patches were available.
- Attackers first abused a /wsproxy WebSocket bypass to reach localhost services and then used a ctrl-service path‑traversal/code‑injection bug to escalate to root on the device.
- Post‑exploit tooling included a setuid privilege binary (ROOTRUN), a Python dropper called KNUCKLEBALL, a custom Java web shell (ORANGETAIL), and a proxy (Suo5) used for persistence and traffic tunneling.
- SonicWall issued hotfixes for CVE‑2026‑15409 and CVE‑2026‑15410 on July 14 and federal guidance followed with CISA adding the flaws to its KEV list while Volexity and Rapid7 published technical details and IoCs.
- Operators should assume possible compromise, re‑image or rebuild affected appliances, reset passwords and TOTP tokens, and hunt logs and memory for indicators because cached credentials and session traffic may have been captured.