SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
SonicWall patched a CVSS 10 pre-auth SSRF in SMA1000 appliances, with no evidence of exploitation.
SonicWall released hotfixes for four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 pre-authentication SSRF in the WorkPlace interface that could let an unauthenticated attacker make the appliance reach internal functions. Affected builds are SMA1000 models 6210, 7210, and 8200v at 12.4.3-03526 and 12.5.0-02952 platform-hotfixes and older; there is no workaround. Authenticated issues include OS command injection CVE-2026-102256 (CVSS 7.8), Zip Slip CVE-2026-102257 (CVSS 7.2), and stored XSS CVE-2026-102258 (CVSS 5.5). SonicWall said it has no evidence these new bugs are exploited, unlike September SMA1000 zero-days CVE-2026-83548 and CVE-2026-83549.
- CVE-2026-102255 is a CVSS 10 pre-auth SSRF in the WorkPlace portal.
- SonicWall reports no evidence this new flaw is being exploited.
- SMA1000 models 6210, 7210, and 8200v on listed builds are affected.
- Three additional authenticated flaws include command injection and Zip Slip RCE.
- Firewall SSL-VPN and SMA 100 Series products are not affected.
Vulnerabilities mentionedAll →
- CVE-2026-10225510.0—Pre-auth SSRF in SonicWall SMA1000 Work Place interfacepublished · SonicWall SMA1000 Appliance (Work Place interface)+1 related
- CVE-2026-1022567.8—Authenticated OS command injection in SonicWall SMA1000published · SonicWall SMA1000
Full article356 words · extracted from securityaffairs.com · click to collapse

SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions.
SonicWall released hotfixes for four vulnerabilities in its SMA1000 remote access appliances, including a critical flaw tracked as CVE-2026-102255 (CVSS score of 10.0. The issue is a pre-authentication SSRF bug in the WorkPlace portal that could let an unauthenticated attacker reach internal functions and perform unauthorized operations.
“A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.” reads the advisory. “By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.”
The vendor said it has found no evidence of exploitation, but recommends applying the fixes.
The vulnerability affects the following product and versions:
| Affected Product | Affected Version(s) |
| SMA1000 Models – 6210, 7210, 8200v | 12.4.3-03526 (platform-hotfix) and older versions. 12.5.0-02952 (platform-hotfix) and older versions. |
The company pointed out that the flaws do not impact SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.
The hotfix is available through the MySonicWall portal, the vendor pointed out that there is no workaround.
The other three flaws all require authentication. CVE-2026-102256, rated CVSS 7.8, is an OS command injection flaw that could allow an authenticated administrator to execute arbitrary commands on the appliance. CVE-2026-102257, rated 7.2, is a Zip Slip vulnerability in the Appliance Management Console that could let an administrator extract files outside the intended directory and achieve remote code execution. CVE-2026-102258, rated 5.5, is a stored XSS flaw that could allow an authenticated administrator to store and execute malicious JavaScript in the management console.
In early September, SonicWall patched two zero-days (CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 (CVSS 7.8)) in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall confirmed that the two SMA 1000 flaws are being exploited in the wild, with attackers likely chaining them to achieve arbitrary code execution.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, SonicWall)