SonicWall Patches Critical Pre-Auth SSRF (CVE-2024-XXXX) in SMA1000
Key Takeaways SonicWall has released patches for four vulnerabilities affecting its SMA 1000 Series appliances. The most critical flaw, CVE-2026-102255, is a pre-authentication SSRF with a CVSS score...
Key Takeaways
- SonicWall has released patches for four vulnerabilities affecting its SMA 1000 Series appliances.
- The most critical flaw, CVE-2026-102255, is a pre-authentication SSRF with a CVSS score of 10.0.
- This critical vulnerability could enable unauthorized remote attackers to access internal network functions.
- Affected organizations must update their SMA 6210, SMA 7210, and SMA 8200v appliances immediately.
SonicWall has issued a series of patches addressing four security vulnerabilities within its Secure Mobile Access (SMA) 1000 Series appliances. Among these, a severe server-side request forgery (SSRF) flaw, identified as CVE-2026-102255, carries the highest possible CVSS score of 10.0, indicating extreme criticality.
Table Of Content
This critical defect could permit an unauthenticated remote attacker to compel the appliance into initiating requests on their behalf, thereby gaining access to internal functions and potentially executing unauthorized operations.
The vendor released security advisory SNWLID-2026-0017 on October 6, 2026. While SonicWall states there is currently no evidence of these vulnerabilities being exploited in the wild, it strongly urges all customers using affected SMA 6210, SMA 7210, and SMA 8200v physical and virtual appliances to implement the provided software updates without delay.
Critical Pre-Authentication SSRF Uncovered
The most severe vulnerability, CVE-2026-102255, impacts the SMA1000 Appliance WorkPlace interface. This flaw originates from an unintended alternative access pathway that effectively transforms the device into a forward proxy. Threat actors could exploit this path to route requests through the appliance, circumventing direct connections to otherwise protected internal network functions.
The severity of this issue is amplified by its pre-authentication nature, meaning attackers do not require valid credentials or user interaction to exploit it. The associated CVSS vector highlights a network-accessible attack with low complexity, capable of significantly impacting confidentiality, integrity, and availability. SonicWall categorizes this vulnerability under CWE-918 for SSRF and CWE-441, which describes an unintended proxy or “confused deputy” scenario.
Additional Security Flaws Identified
Beyond the critical SSRF, three other vulnerabilities were addressed:
- CVE-2026-102256: Post-Authentication Command Injection (CVSS 7.8)
This flaw could allow an authenticated administrator, under specific conditions, to execute arbitrary operating-system commands, potentially leading to remote code execution. SonicWall’s advisory does not indicate a possible chain with the critical SSRF vulnerability. - CVE-2026-102257: Zip Slip Vulnerability (CVSS 7.2)
Affecting the Appliance Management Console (AMC), this Zip Slip vulnerability could enable path traversal. A specially crafted archive might cause files to be extracted outside their intended directories, potentially leading to remote code execution. - CVE-2026-102258: Stored Cross-Site Scripting (CVSS 5.5)
Also found in the AMC, this stored XSS vulnerability could allow an authenticated administrator, under certain conditions, to inject and execute arbitrary JavaScript within the management console.
SonicWall acknowledged Benoît Sevens of Anthropic for reporting the SSRF and command injection vulnerabilities. Brian Mariani, reporting through Trend Micro’s Zero Day Initiative (ZDI-CAN-28924), was credited for the Zip Slip issue, and DigitalCanion SA was recognized for the stored XSS vulnerability.
Affected Versions and Required Updates
The vulnerabilities impact SMA 1000 Series appliances running firmware versions 12.4.3-03526 and earlier, as well as 12.5.0-02952 and earlier. Customers must upgrade their appliances to platform hotfix 12.4.3-03670 or later, or 12.5.0-03082 or later, depending on their current software branch. These updates are available via MySonicWall. SonicWall has not provided any workarounds for these issues, emphasizing the need for direct patching.
It is important to note that SSL-VPN services operating on SonicWall firewalls and the SMA 100 Series product line are not affected by this advisory. This distinction is crucial for administrators to accurately scope their patching efforts.
Previously, in September, SonicWall addressed other SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549) that were actively exploited. The patches for those issues, 12.4.3-03526 and 12.5.0-02952, are now themselves listed as vulnerable to this new set of flaws. Therefore, installing the September updates does not confer protection against the newly disclosed October vulnerabilities. Organizations must verify each appliance’s installed build against the latest fixed versions and perform the necessary upgrades, rather than assuming prior patches provide comprehensive security.
What You Should Do
- Immediately identify all SonicWall SMA 1000 Series appliances (SMA 6210, SMA 7210, and SMA 8200v) within your environment.
- Verify the current firmware version of each appliance. If running 12.4.3-03526 or earlier, or 12.5.0-02952 or earlier, an upgrade is mandatory.
- Download and apply the latest hotfixes: 12.4.3-03670 or later, or 12.5.0-03082 or later, from MySonicWall.
- Do not rely on previous updates as a substitute for applying these new patches. Confirm the specific build number post-update.
- Monitor SonicWall’s security advisories for any further updates or emerging threats.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.