---
schema: 1
kind: vulnerability
title: "CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, and it affects the hotfix builds that closed the September zero-days (no exploitation reported)"
headline: "SonicWall patches a third pre-auth CVSS 10.0 SMA1000 SSRF; the September hotfix builds are affected"
summary: >
  SonicWall's advisory SNWLID-2026-0017 (2026-10-06) fixes four SMA1000 flaws, led by CVE-2026-102255, a
  pre-authentication server-side request forgery in the Work Place interface (CVSS 3.0 10.0) that affects
  12.4.3-03526 and 12.5.0-02952, the hotfixes issued for the September zero-days. SonicWall reports no
  exploitation, but the two earlier unauthenticated Work Place SSRF flaws this year were exploited, each
  paired with an administrator-only command-execution flaw; fixed builds are 12.4.3-03670 and 12.5.0-03082.
discovered_at: "2026-10-08T04:50:00Z"
updated_at: null
event_date: "2026-10-06"
run_id: 2026-10-08T0404Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, pre-auth, patch-available]
regions: [global, europe]
sectors: [public-sector, technology]
entities: ["product:sonicwall-sma-1000"]
techniques: [T1190, T1059]
affected_products: ["SonicWall SMA1000"]
cves:
  - id: CVE-2026-102255
    cvss: "10.0 (CVSS 3.0)"
    epss: null
    type: ssrf
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "SMA1000 6210, 7210, 8200v: 12.4.3-03526 and older; 12.5.0-02952 and older"
    fixed: "12.4.3-03670; 12.5.0-03082"
  - id: CVE-2026-102256
    cvss: "7.8 (CVSS 3.0)"
    epss: null
    type: rce
    vector: zero-click
    auth: admin-required
    status: [patch-available]
    affected: "SMA1000 6210, 7210, 8200v: 12.4.3-03526 and older; 12.5.0-02952 and older"
    fixed: "12.4.3-03670; 12.5.0-03082"
  - id: CVE-2026-102257
    cvss: "7.2 (CVSS 3.0)"
    epss: null
    type: path-traversal
    vector: zero-click
    auth: admin-required
    status: [patch-available]
    affected: "SMA1000 6210, 7210, 8200v: 12.4.3-03526 and older; 12.5.0-02952 and older"
    fixed: "12.4.3-03670; 12.5.0-03082"
  - id: CVE-2026-102258
    cvss: "5.5 (CVSS 3.0)"
    epss: null
    type: xss
    vector: user-interaction
    auth: admin-required
    status: [patch-available]
    affected: "SMA1000 6210, 7210, 8200v: 12.4.3-03526 and older; 12.5.0-02952 and older"
    fixed: "12.4.3-03670; 12.5.0-03082"
sources:
  - url: "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017"
    publisher: "SonicWall PSIRT (advisory SNWLID-2026-0017)"
    date: "2026-10-06"
    role: primary
  - url: "https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html"
    publisher: "The Hacker News"
    date: "2026-10-07"
    role: corroborating
  - url: "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1275/"
    publisher: "CERT-FR"
    date: "2026-10-07"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/"
    publisher: "BleepingComputer"
    date: "2026-10-07"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/13034"
    publisher: "NCSC Switzerland (Security Hub advisory)"
    date: "2026-10-07"
    role: corroborating
  - url: "https://cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-1017"
    publisher: "Canadian Centre for Cyber Security (AV26-1017)"
    date: "2026-10-07"
    role: corroborating
closed_sources: []
evidence:
  - quote: "There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild."
    publisher: "SonicWall PSIRT (advisory SNWLID-2026-0017)"
  - quote: "It is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login."
    publisher: "The Hacker News"
  - quote: "12.4.3-03670 and higher versions are fixed."
    publisher: "The Hacker News"
  - quote: "12.5.0-03082 and higher versions are fixed."
    publisher: "The Hacker News"
verification: multi-source
sourcing_note: >
  The fixed builds are taken from The Hacker News and CERT-FR, which agree; the Canadian Cyber Centre
  bulletin lists the same two builds as affected "and prior". NCSC Switzerland, CERT-FR, BleepingComputer
  and The Hacker News restate the vendor advisory; none reports independent observation of the flaws.
confidence: high
references:
  - 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited
  - 2026-09-03/cve-2026-83548-83549-sonicwall-sma1000-ssrf-cmd-injection
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Install SonicWall's platform hotfix 12.4.3-03670 or 12.5.0-03082 (or higher) on every SMA1000 6210, 7210 and 8200v, including appliances already on the 12.4.3-03526 or 12.5.0-02952 hotfix from September; the appliance restarts when the installation finishes and no workaround is listed."
updates: []
migrated_from: null
---

SonicWall's advisory SNWLID-2026-0017 of 2026-10-06 fixes four flaws in the SMA1000 secure remote-access appliances (models 6210, 7210 and 8200v). CVE-2026-102255 (CVSS 3.0 10.0) is a pre-authentication server-side request forgery in the Work Place interface, attributed to an unintended alternate access path, through which a remote unauthenticated attacker can direct the appliance to issue requests on their behalf, reach internal functionality and perform unauthorized operations ([SonicWall PSIRT, 2026-10-06](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017)). The other three flaws need a login: an OS command injection that lets an administrator execute commands (CVE-2026-102256, 7.8), a Zip Slip in the Appliance Management Console that leads to code execution (CVE-2026-102257, 7.2) and a stored cross-site scripting flaw in that console (CVE-2026-102258, 5.5) ([SonicWall PSIRT, 2026-10-06](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017)). SonicWall says there is currently no evidence that any of them is exploited ([SonicWall PSIRT, 2026-10-06](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017)).

The pre-authentication flaw is not routine because of what came before it. The Hacker News counts it as the third time this year that SonicWall has fixed a 10.0-rated Work Place SSRF that needs no login; in July and September SonicWall said it had investigated attacks on the earlier pairs ("multiple cases" and "a case"), each pair combining an SSRF that needs no login with a second flaw that lets a logged-in administrator run commands ([The Hacker News, 2026-10-07](https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html)). CERT-FR notes that such pairs have been actively exploited several times this year on this product ([CERT-FR, 2026-10-07](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1275/)). The affected builds include 12.4.3-03526 and 12.5.0-02952, the hotfixes SonicWall named on 1 September for the two exploited flaws, so an appliance patched against that chain is still affected ([The Hacker News, 2026-10-07](https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html)). Fixed builds are 12.4.3-03670 and 12.5.0-03082 and higher ([The Hacker News, 2026-10-07](https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html); [CERT-FR, 2026-10-07](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1275/)), whereas the Canadian Cyber Centre's bulletin lists the same two builds as affected "and prior" ([Canadian Cyber Centre, 2026-10-07](https://cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-1017)). Shadowserver tracks over 400 internet-exposed SMA1000 appliances, some of which may already be patched, and BleepingComputer says government agencies and managed service providers use the product to give VPN access to internal applications ([BleepingComputer, 2026-10-07](https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/)). NCSC Switzerland published an advisory on 2026-10-07 and lists the exploitation status as unknown ([NCSC Switzerland, 2026-10-07](https://security-hub.ncsc.admin.ch/#/posts/13034)).

**Exposure:** SMA1000 6210, 7210 and 8200v whose Work Place interface is reachable from untrusted networks, on 12.4.3-03526 or older or 12.5.0-02952 or older, which includes appliances that already took the September hotfix; the SMA 100 series and SSL-VPN on SonicWall firewalls are not affected ([The Hacker News, 2026-10-07](https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html)).

**Detection:** SonicWall's advisory title calls the access path an unintended forward proxy, so the telemetry is the Work Place web access log, looking for requests that name internal hosts or services as the destination, and connections that the appliance itself opens to internal management endpoints without a user session behind them ([SonicWall PSIRT, 2026-10-06](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017)). On an appliance that was exposed before the September hotfix, SonicWall's earlier guidance still applies: check for indicators of compromise and, if any are found, re-image or redeploy the appliance, change user and administrator passwords and reset the TOTP tokens; SonicWall has given no such instruction for the new flaws ([The Hacker News, 2026-10-07](https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html)).

**Defender takeaway:** install 12.4.3-03670 or 12.5.0-03082 (or higher) on every SMA1000 this week, including appliances already on the September hotfix; the hotfix restarts the appliance and SonicWall lists no workaround, so plan the maintenance window rather than waiting for exploitation to be reported ([The Hacker News, 2026-10-07](https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html)).
