SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10
SonicWall patched four SMA 1000 flaws, including an unauthenticated SSRF rated CVSS 10.0.
SonicWall advisory SNWLID-2026-0017, published October 6, 2026, patches four flaws in SMA 1000 Series appliances, including physical and virtual SMA 6210, 7210, and 8200v. CVE-2026-102255 is a pre-authentication SSRF (CVSS 10.0) in the WorkPlace interface that can make the device act as an unintended forward proxy. CVE-2026-102256 is authenticated command injection scored 7.8, CVE-2026-102257 is a Zip Slip issue in the management console scored 7.2 that can lead to remote code execution, and CVE-2026-102258 is stored XSS scored 5.5. SonicWall says it has no evidence of exploitation and no workaround; builds 12.4.3-03526 and earlier and 12.5.0-02952 and earlier need 12.4.3-03670 or 12.5.0-03082. SMA 100 Series and firewall SSL-VPN are unaffected, and September fixes for CVE-2026-83548 and CVE-2026-83549 do not resolve these bugs.