AI analysis
CVE-2026-102257 is a Zip Slip path-traversal flaw (CWE-22) in the SonicWall SMA 1000 Appliance Management Console. An attacker who can supply a specially crafted archive to the AMC interface can cause files to be extracted outside the intended destination directory. Successful exploitation can lead to remote code execution on the appliance. The issue affects the SMA 1000 AMC; affected version ranges are not stated in the published data, and CVSS has not yet been scored. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Apply the SonicWall PSIRT fix for SMA 1000 Appliance Management Console as soon as it is available for your build, and treat the management interface as untrusted until patched. Until then, keep AMC off the public internet, restrict it to trusted admin networks, and review recent archive uploads and unexpected files written outside the intended extraction directory.
Affected
| SonicWall SMA1000 Appliance Management Console (AMC) | — |
Estimated exposure
moderateLow thousands of internet-exposed appliances (order-of-magnitude estimate) — SMA 1000 is an enterprise remote-access appliance, not a mass consumer product; public internet scans of this product class have historically shown on the order of a few thousand exposed hosts.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.