CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, and it affects the hotfix builds that closed the September zero-days (no exploitation reported)
SonicWall patches a third pre-auth CVSS 10.0 SMA1000 SSRF; the September hotfix builds are affected
Defender actions
- Install SonicWall's platform hotfix 12.4.3-03670 or 12.5.0-03082 (or higher) on every SMA1000 6210, 7210 and 8200v, including appliances already on the 12.4.3-03526 or 12.5.0-02952 hotfix from September; the appliance restarts when the installation finishes and no workaround is listed.
Analysis
SonicWall's advisory SNWLID-2026-0017 of 2026-10-06 fixes four flaws in the SMA1000 secure remote-access appliances (models 6210, 7210 and 8200v). CVE-2026-102255 (CVSS 3.0 10.0) is a pre-authentication server-side request forgery in the Work Place interface, attributed to an unintended alternate access path, through which a remote unauthenticated attacker can direct the appliance to issue requests on their behalf, reach internal functionality and perform unauthorized operations (SonicWall PSIRT, 2026-10-06). The other three flaws need a login: an OS command injection that lets an administrator execute commands (CVE-2026-102256, 7.8), a Zip Slip in the Appliance Management Console that leads to code execution (CVE-2026-102257, 7.2) and a stored cross-site scripting flaw in that console (CVE-2026-102258, 5.5) (SonicWall PSIRT, 2026-10-06). SonicWall says there is currently no evidence that any of them is exploited (SonicWall PSIRT, 2026-10-06).
The pre-authentication flaw is not routine because of what came before it. The Hacker News counts it as the third time this year that SonicWall has fixed a 10.0-rated Work Place SSRF that needs no login; in July and September SonicWall said it had investigated attacks on the earlier pairs ("multiple cases" and "a case"), each pair combining an SSRF that needs no login with a second flaw that lets a logged-in administrator run commands (The Hacker News, 2026-10-07). CERT-FR notes that such pairs have been actively exploited several times this year on this product (CERT-FR, 2026-10-07). The affected builds include 12.4.3-03526 and 12.5.0-02952, the hotfixes SonicWall named on 1 September for the two exploited flaws, so an appliance patched against that chain is still affected (The Hacker News, 2026-10-07). Fixed builds are 12.4.3-03670 and 12.5.0-03082 and higher (The Hacker News, 2026-10-07; CERT-FR, 2026-10-07), whereas the Canadian Cyber Centre's bulletin lists the same two builds as affected "and prior" (Canadian Cyber Centre, 2026-10-07). Shadowserver tracks over 400 internet-exposed SMA1000 appliances, some of which may already be patched, and BleepingComputer says government agencies and managed service providers use the product to give VPN access to internal applications (BleepingComputer, 2026-10-07). NCSC Switzerland published an advisory on 2026-10-07 and lists the exploitation status as unknown (NCSC Switzerland, 2026-10-07).
Cited evidence
There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.
It is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login.
12.4.3-03670 and higher versions are fixed.
12.5.0-03082 and higher versions are fixed.
Sources6
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.