SonicWall Patches CVSS 10.0 Pre-Auth SSRF in SMA1000 Appliances

SonicWall fixed four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 unauthenticated SSRF in the WorkPlace portal. No exploitation has been reported.
Table of Contents
    Add a header to begin generating the table of contents

    SonicWall has released fixed firmware for its SMA1000 remote-access appliances to address four vulnerabilities, including CVE-2026-102255, a server-side request forgery flaw in the WorkPlace portal that carries the maximum CVSS score of 10.0 and requires no authentication to exploit.

    SonicWall published the advisory and patches on October 6. The company says it has no evidence that any of the four flaws is being exploited.

    CVE-2026-102255 Gives Unauthenticated Attackers Access to Internal Functionality

    The critical flaw, tracked as CVE-2026-102255, is a server-side request forgery in the SMA1000 WorkPlace portal. An attacker does not need credentials. According to the advisory, a successful attack lets the attacker reach internal functionality on the appliance and carry out unauthorized operations.

    Server-side request forgery flaws cause a server to issue requests on an attacker’s behalf, which is how functionality not meant to be exposed to outside users becomes reachable. The CVSS 10.0 rating reflects the combination of no authentication requirement and the level of access described.

    The Three Other SMA1000 Flaws Patched Alongside It

    SonicWall fixed three further vulnerabilities in the same release:

    • CVE-2026-102256, an OS command injection flaw rated CVSS 7.8.
    • CVE-2026-102257, a Zip Slip flaw rated CVSS 7.2.
    • CVE-2026-102258, a stored cross-site scripting flaw rated CVSS 5.5.

    The two most serious of the four were found by Benoit Sevens of Anthropic, according to the advisory.

    Affected Models and Firmware Versions

    The advisory lists the SMA1000 models 6210, 7210 and 8200v as affected. Two firmware branches carry the vulnerable code: version 12.4.3-03526 and older, and version 12.5.0-02952 and older.

    Fixed Firmware for Both Branches

    SonicWall released a fix for each branch. Customers on the 12.4.3 line need version 12.4.3-03670 or newer, and customers on the 12.5.0 line need version 12.5.0-03082 or newer. No workaround is described in the information available, so installing the updated firmware is the stated remedy.

    The WorkPlace portal is the component at the center of the most serious flaw. SonicWall’s advisory describes CVE-2026-102255 as a way for an attacker with no account to reach internal functionality of the appliance and perform operations the attacker is not authorized to perform. The other three flaws sit at lower severity levels, with scores of 7.8, 7.2 and 5.5, but all four were fixed in the same firmware releases and all four affect the same two firmware branches. Both branches received separate fixes, so a unit on the 12.4.3 line updates to build 12.4.3-03670 or later, while a unit on the 12.5.0 line updates to build 12.5.0-03082 or later. SonicWall published the advisory and the patches together on October 6, so fixed firmware has been available since the day the flaws became public.

    Exploitation Status and Exposure

    SonicWall says it has seen no evidence of exploitation for any of the four flaws. The statement describes the company’s current knowledge at the time of the advisory and does not rule out later attacks.

    Remote-access appliances sit at the network perimeter and handle authentication for users connecting from outside, which is why they are frequent targets for attackers. A pre-authentication flaw with a 10.0 score on that kind of device raises the exposure of every unpatched unit for as long as it stays reachable from the internet.

    What the Vulnerability Combination Means for Defenders

    The four flaws span several bug classes. The SSRF opens the door without credentials, while the command injection, Zip Slip and stored XSS flaws cover other parts of the appliance’s attack surface. The advisory does not describe how, or whether, the flaws can be chained, and SonicWall has not published exploitation details.

    Benoit Sevens of Anthropic found the two highest-severity issues. The advisory does not say how Sevens identified the bugs.

    Administrators running SMA1000 units can confirm their exposure by checking the installed firmware against the affected and fixed version numbers above. Until a unit runs a fixed build, the WorkPlace portal remains the reachable component for CVE-2026-102255.

    Related Posts