Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > SonicWall Fixes Maximum-Severity SMA1000 Flaw Allowing Pre-Login Internal Requests
SonicWall Fixes Maximum-Severity SMA1000 Flaw Allowing Pre-Login Internal Requests
Read Time:3 Minute, 17 Second

SonicWall customers running SMA1000 remote-access appliances have a new urgent patching task. The vendor has fixed four security defects, including a maximum-severity server-side request forgery (SSRF) vulnerability that can be triggered over the network before an attacker signs in. Although SonicWall says it has not observed exploitation, the combination of pre-authentication access, low attack complexity and a security appliance positioned at the network edge gives defenders little reason to delay.

A CVSS 10 route through the appliance

The headline issue, CVE-2026-102255, affects the Appliance WorkPlace interface in the SMA 1000 Series. An unintended alternate access path allows the product to behave as a forward proxy. In practical terms, a remote attacker could instruct the appliance to make requests on their behalf, potentially reaching functions or systems that are not normally exposed to the internet.

SonicWall assigned the flaw a CVSS score of 10.0. The rating reflects a network-accessible attack that requires neither credentials nor user interaction and may have a high impact on confidentiality, integrity and availability. The company maps the weakness to SSRF and the “confused deputy” pattern, in which a trusted component is tricked into exercising its authority for an untrusted party.

The vulnerable products are the physical SMA 6210 and SMA 7210 appliances and the virtual SMA 8200v. SonicWall firewall SSL-VPN services and the separate SMA 100 Series are not affected by this advisory, so asset owners should identify models and software branches precisely rather than assume that every SonicWall remote-access deployment shares the same exposure.

Three additional flaws raise the stakes

Advisory SNWLID-2026-0017 also addresses three authenticated vulnerabilities. CVE-2026-102256 is a command-injection issue rated 7.8. Under the required conditions, an administrator could execute operating-system commands and achieve remote code execution. The advisory does not state that the critical SSRF can be chained with this bug, so defenders should not treat such a combination as confirmed.

CVE-2026-102257, rated 7.2, is a Zip Slip path-traversal flaw in the Appliance Management Console. A malicious archive may write files outside its intended extraction directory, opening another route to code execution. CVE-2026-102258 is a stored cross-site scripting issue rated 5.5 that could let an authenticated administrator place JavaScript in the management console.

Taken together, the findings show why management interfaces deserve the same hardening and monitoring as other high-value infrastructure. Even flaws requiring administrator access matter if an account is phished, reused or compromised through a separate incident.

September updates are no longer enough

Affected versions are 12.4.3-03526 and earlier, plus 12.5.0-02952 and earlier. Customers on the 12.4 branch should install platform-hotfix 12.4.3-03670 or newer. Those on 12.5 should move to 12.5.0-03082 or newer. SonicWall distributes the updates through MySonicWall and lists no workaround.

This version detail is especially important because builds released for separate, actively exploited SMA1000 vulnerabilities in September are now within the affected range. A team that applied last month’s fixes may reasonably believe its appliance is current, but that work does not address the newly disclosed October issues.

What security teams should do now

  • Inventory SMA 6210, SMA 7210 and SMA 8200v systems, including standby and disaster-recovery instances.
  • Confirm the installed build directly on each appliance and deploy the correct October hotfix.
  • Restrict management access to trusted networks and review logs for unusual outbound or internal requests originating from the appliance.
  • Examine administrator accounts, recent configuration changes and unexpected archive uploads.
  • Retest external exposure after upgrading and document the fixed build in the asset register.

The absence of known exploitation is useful context, not a guarantee of safety. Edge appliances are attractive targets because they bridge untrusted networks and internal services. With no mitigation offered and fixed releases available, rapid installation and follow-up monitoring are the clearest risk-reduction steps.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on SonicWall Fixes Maximum-Severity SMA1000 Flaw Allowing Pre-Login Internal Requests, use the discussion on Forum.

>> forum community

Comments

Leave a Reply