SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
SonicWall patched a CVSS 10 pre-auth SSRF in SMA1000 appliances, with no evidence of exploitation.
SonicWall released hotfixes for four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 pre-authentication SSRF in the WorkPlace interface that could let an unauthenticated attacker make the appliance reach internal functions. Affected builds are SMA1000 models 6210, 7210, and 8200v at 12.4.3-03526 and 12.5.0-02952 platform-hotfixes and older; there is no workaround. Authenticated issues include OS command injection CVE-2026-102256 (CVSS 7.8), Zip Slip CVE-2026-102257 (CVSS 7.2), and stored XSS CVE-2026-102258 (CVSS 5.5). SonicWall said it has no evidence these new bugs are exploited, unlike September SMA1000 zero-days CVE-2026-83548 and CVE-2026-83549.