TL;DR
SonicWall has fixed four flaws in its SMA1000 remote access appliances, led by CVE-2026-102255, a SonicWall SMA1000 vulnerability with a perfect CVSS score of 10.0. The pre-authentication SSRF bug lets a remote attacker push the appliance into reaching internal functions. Three more post-authentication bugs can lead to code execution or stored XSS.
Turn SonicWall CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
SMA1000 appliances give remote staff secure access to company networks. As a result, they sit right at the network edge. A flaw that needs no login on such a device deserves fast action. Because it needs no credentials, this SonicWall SMA1000 vulnerability is the most urgent of the four fixes.
For now, SonicWall says, “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.” No public proof-of-concept has been confirmed either.
How the Attacks Work
Pre-Auth SSRF (CVE-2026-102255)
The bug lives in the Work Place interface and stems from “an unintended alternate access path.” By abusing it, an unauthenticated attacker could “direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.”
Post-Auth Flaws
CVE-2026-102256 (CVSS 7.8) is an OS command injection that lets an administrator run arbitrary commands. Next, CVE-2026-102257 (CVSS 7.2) is a Zip Slip bug in the Appliance Management Console. A crafted archive can write files outside the intended folder, “resulting in remote code execution.” Finally, CVE-2026-102258 (CVSS 5.5) is a stored XSS flaw in the same console.
Affected Versions
The flaws hit SMA1000 models 6210, 7210 and 8200v running:
- 12.4.3-03526 (platform-hotfix) and older
- 12.5.0-02952 (platform-hotfix) and older
Notably, SSL-VPN on SonicWall firewalls and the SMA 100 series are not affected.
Patch and Mitigation Steps
No workaround exists. Upgrade to platform-hotfix 12.4.3-03670 or 12.5.0-03082 and later from mysonicwall.com. SonicWall “strongly advises users of the SMA1000 series appliances to upgrade.” Given its perfect score, treat this SonicWall SMA1000 vulnerability as a top patching priority.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!