SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
SonicWall patched a CVSS 10.0 pre-auth SSRF in SMA1000 WorkPlace plus three authenticated flaws.
SonicWall released hotfixes for four flaws in SMA1000 models 6210, 7210, and 8200v on platform versions 12.4.3 and 12.5.0. CVE-2026-102255 is a pre-authentication server-side request forgery in the WorkPlace portal, rated CVSS 10.0, that could let an unauthenticated attacker reach internal functions. The other issues require login: OS command injection CVE-2026-102256 (CVSS 7.8), Zip Slip CVE-2026-102257 (7.2), and stored XSS CVE-2026-102258 (5.5). SonicWall says it has no evidence any of the four is being exploited. SSL-VPN and the SMA 100 Series are not affected; fixed versions are 12.4.3-03670 and 12.5.0-03082 or higher.