SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

SonicWall has disclosed CVE-2026-102255, a critical pre-authentication SSRF vulnerability in SMA 1000 Work Place that can let unauthenticated attackers reach internal functionality and perform unauthorized operations. The advisory also covers three additional SMA 1000 issues. Fixed platform-hotfixes are available; SonicWall reports no evidence of in-the-wild exploitation at publication.

Oct 8, 2026By Bapanapalli Prem Sai Siddhik
threat intelligence

Summary

SonicWall has published advisory SNWLID-2026-0017 addressing multiple issues in SMA 1000 series appliances. The most severe is CVE-2026-102255, a critical pre-authentication server-side request forgery (SSRF) flaw in the Work Place interface. An unauthenticated attacker can abuse an unintended alternate access path so the appliance issues requests on their behalf, reaches internal functionality, and performs unauthorized operations. SonicWall states there is currently no evidence that the vulnerabilities in this release are being exploited in the wild and strongly advises upgrading to a fixed platform-hotfix.

The same advisory also addresses CVE-2026-102256, CVE-2026-102257, and CVE-2026-102258. Descriptions of those issues are in the official SonicWall advisory.

Vulnerability Details

CVE ID CVSS Score Type
CVE-2026-102255 10.0 CWE-918: Server-Side Request Forgery (SSRF)
CWE-441: Unintended Proxy or Intermediary

Technical Information

Critical Unauthenticated No User Interaction SSRF

CVE-2026-102255 — Pre-authentication SSRF via Unintended Forward-Proxy

The flaw is in the SMA 1000 Appliance Work Place interface. SonicWall describes it as pre-authentication server-side request forgery caused by an unintended alternate access path. That path effectively allows the appliance to act as an unintended intermediary: a remote attacker can abuse it so the device issues HTTP requests on the attacker’s behalf.

Because those requests originate from the appliance, they can reach internal functionality that trusts the SMA 1000 and support unauthorized operations that would not normally be available without authentication. SonicWall classifies the weakness under server-side request forgery and unintended proxy or intermediary behavior.

The issue is specific to the SMA 1000 series Work Place surface. SonicWall states that SSL-VPN running on SonicWall firewall products is not affected, and that the SMA 100 Series product line is outside the affected set for this advisory. Physical and virtual SMA 1000 models in scope are 6210, 7210, and 8200v.

SonicWall reports no evidence that the vulnerabilities addressed in this release are being exploited in the wild at the time of publication. No workaround is provided; the published remediation is to upgrade to a fixed platform-hotfix.

Impact

  • Unauthenticated access to internal functionality
    A remote attacker without credentials can coerce the SMA 1000 appliance to make requests that reach internal functions and support unauthorized operations on the device or trusted internal paths.

Affected Versions

Affected products and versions per SonicWall:

  • SMA1000 models 6210, 7210, and 8200v — 12.4.3-03526 (platform-hotfix) and older
  • SMA1000 models 6210, 7210, and 8200v — 12.5.0-02952 (platform-hotfix) and older

These issues do not affect SSL-VPN on SonicWall firewalls or the SMA 100 Series product line.

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic ID Tactic
T1190 Exploit Public-Facing Application TA0001 Initial Access
T1090 Proxy TA0011 Command and Control

Mitigation and Recommendations

SonicWall strongly advises SMA 1000 users to upgrade to a fixed platform-hotfix. No workaround is published for this advisory.

Fixed Builds

  • SMA1000 models 6210, 7210, and 8200v — 12.4.3-03670 (platform-hotfix) and higher
  • SMA1000 models 6210, 7210, and 8200v — 12.5.0-03082 (platform-hotfix) and higher

The latest platform-hotfix is available for download on mysonicwall.com.

Recommended Actions

  • Upgrade affected SMA 1000 appliances to a fixed platform-hotfix listed above.
  • Confirm the running build after upgrade in the appliance management interface.
  • Limit unnecessary internet exposure of the Work Place interface where operationally possible until fixed software is in place.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
vulnerability researchCritical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

CVE Research

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026

Open New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service
threat intelligenceNew NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

CVE Research

New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

Citrix has disclosed CVE-2026-88779, a high-severity memory overflow in NetScaler ADC and NetScaler Gateway that can cause denial of service when the appliance is configured as a SAML service provider or identity provider. Targeted attacks on unmitigated deployments have been observed. This article covers impact, affected versions, configuration checks, temporary Global Deny List guidance, and fixed builds.

Oct 8, 2026

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026