Full Report
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being
Analysis Summary
# Vulnerability: SonicWall SMA1000 Series Multiple Vulnerabilities
## CVE Details
- **CVE ID:** CVE-2026-102255
- **CVSS Score:** 10.0 (Critical)
- **CWE:** Server-Side Request Forgery (SSRF)
- **CVE ID:** CVE-2026-102256
- **CVSS Score:** 7.8 (High)
- **CWE:** OS Command Injection / Remote Code Execution (RCE)
- **CVE ID:** CVE-2026-102257
- **CVSS Score:** 7.2 (High)
- **CWE:** Zip Slip (Path Traversal via Archive Extraction)
- **CVE ID:** CVE-2026-102258
- **CVSS Score:** 5.5 (Medium)
- **CWE:** Stored Cross-Site Scripting (XSS)
## Affected Systems
- **Products:** SonicWall SMA1000 Series (Models 6210, 7210, and 8200v).
- **Versions:**
- Version 12.4.3: 12.4.3-03526 and older.
- Version 12.5.0: 12.5.0-02952 and older.
- **Configurations:** The critical SSRF (CVE-2026-102255) affects the **WorkPlace** portal; other flaws affect the **Appliance Management Console (AMC)**.
## Vulnerability Description
The primary flaw (CVE-2026-102255) is a pre-authentication SSRF vulnerability located in the WorkPlace portal. It stems from an unintended access path that allows an unauthenticated remote attacker to send requests through the appliance to reach internal functions and perform unauthorized operations.
The secondary flaws include an OS command injection (CVE-2026-102256) and a Zip Slip vulnerability (CVE-2026-102257) in the management console, both of which could lead to RCE, though they require varying levels of authentication (User or Administrator login).
## Exploitation
- **Status:** Not currently exploited in the wild (as of October 7, 2026).
- **Complexity:** Low (for the 10.0 SSRF).
- **Attack Vector:** Network.
- **PoC Availability:** Not publicly disclosed in the article.
## Impact
- **Confidentiality:** High (Internal functions and data can be accessed/manipulated).
- **Integrity:** High (Unauthorized operations and RCE potential).
- **Availability:** High (Potential for full system takeover or disruption).
## Remediation
### Patches
SonicWall has released the following hotfixes. Administrators should apply these immediately as the appliance will restart upon installation:
- **For 12.4.3:** Upgrade to **12.4.3-03670** or higher.
- **For 12.5.0:** Upgrade to **12.5.0-03082** or higher.
### Workarounds
- No specific workarounds have been provided by the vendor. Immediate patching is the only recommended course of action.
## Detection
- **Indicators of Compromise:** Review logs for unusual requests to the `/WorkPlace` portal or unexpected internal network traffic originating from the SMA appliance.
- **Detection methods and tools:** Monitor the Appliance Management Console (AMC) for unauthorized login attempts or unusual file extraction activities.
## References
- **SonicWall Security Advisory:** hxxps://psirt.global.sonicwall[.]com/vuln-detail/SNWLID-2026-0017
- **CVE Database:** hxxps://www.cve[.]org/CVERecord?id=CVE-2026-102255
- **News Source:** hxxps://thehackernews[.]com/2026/10/sonicwall-patches-cvss-100-pre.html