CVSS
7.2
CVSS v3.1
EPSS
76.3%
Exploit Prediction Score
Published
July 14, 2026
Exploitability
Exploited in the wild (CISA KEV)
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).