
SonicWall SMA1000 SSRF Hotfix Released
SonicWall has released hotfixes for four SMA1000 flaws, including a CVSS 10.0 pre-authentication SSRF that lets unauthenticated attackers reach internal functio…
SonicWall has released hotfixes for its SMA1000 remote access appliances, closing four security flaws including a critical server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale. The most serious issue, tracked as CVE-2026-102255, exists in WorkPlace, the portal that SMA1000 users log in to. Because the flaw is pre-authentication, an attacker does not need a username or password to exploit it. SonicWall said in an advisory dated October 6 that an attacker who abuses the unintended access path could reach internal functionality and perform unauthorized operations, though the company did not specify which functions. SonicWall added that it has no evidence any of the four flaws is being used in attacks.
The four flaws affect SMA1000 models 6210, 7210 and 8200v. For version 12.4.3, builds up to and including 12.4.3-03526 are affected, while 12.4.3-03670 and higher are fixed. For version 12.5.0, builds up to and including 12.5.0-02952 are affected, while 12.5.0-03082 and higher are fixed. SonicWall highlighted that the affected versions include 12.4.3-03526 and 12.5.0-02952, which the company had named on September 1 as the fix for two flaws it reported as exploited. This means an appliance still running those September builds needs the new hotfix. The hotfix is available from the MySonicWall portal, and the appliance restarts automatically when installation finishes. No workaround is listed. SonicWall also confirmed that SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.
The other three flaws require an attacker to have already logged in. CVE-2026-102256 is an OS command injection flaw that could lead to remote code execution; it is rated 7.8 and requires an administrator login. CVE-2026-102257 is a Zip Slip issue in the Appliance Management Console (AMC), where a specially made archive can extract files outside the intended folder and potentially lead to remote code execution; it is rated 7.2 and requires a login. CVE-2026-102258 is a stored cross-site scripting (XSS) flaw in the AMC, rated 5.5 and also requiring an administrator login. All three lower-severity flaws still matter because a compromised administrator account or a lower-level insider could use them to take control of the appliance.
This is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login. On July 14, SonicWall disclosed CVE-2026-15409 and CVE-2026-15410, and on September 1 it disclosed CVE-2026-83548 and CVE-2026-83549. In both earlier cases, SonicWall said it had investigated attacks exploiting the flaws: multiple cases in July and a case in September. Each earlier pair consisted of an SSRF flaw requiring no login and a second flaw that allowed a logged-in administrator to run commands on the appliance. SonicWall's own staff found both of those pairs. The four new flaws were reported by outside researchers: Benoît Sevens of Anthropic found CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA found the other two, with one reported through Trend Micro's Zero Day Initiative. According to Rapid7, in the July attacks CVE-2026-15409 allowed an unauthenticated attacker to open a tunnel to services that respond only inside the appliance, after which the attacker could run commands and use CVE-2026-15410 to gain root access, meaning full control. SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way. In its July and September advisories, SonicWall told customers to check appliances for indicators of compromise and, if any were found, to re-image or redeploy the appliance, change user and administrator passwords, and reset the TOTP tokens used for one-time login codes. The company has given no such instruction for the four new flaws.
For businesses that depend on remote access to internal applications, this is a reminder that the gateway itself is a critical security boundary. A single unpatched appliance can become the entry point an attacker uses to reach internal functions without any credentials. AEU-I offers security-first IT and infrastructure consulting that can help teams review remote access deployments and plan timely patch rollouts. Until the hotfix is applied, SonicWall has not provided a workaround, so updating is the primary defense.
How to Protect Yourself
- If your company uses a SonicWall SMA1000 remote access appliance, ask your IT team to confirm it is running the newest hotfix and has been restarted.
- If you are responsible for one of these appliances, download the hotfix from the MySonicWall portal and apply it now; the device will restart on its own when done.
- Check the version in the appliance management screen: version 12.4.3 must be at least 12.4.3-03670, and version 12.5.0 must be at least 12.5.0-03082.
- Never leave the login page for remote work tools directly reachable from the whole internet; put it behind another security layer or restrict access to known addresses.
- If you use such a portal as an employee, be alert for unexpected login pages or pop-ups and tell your IT team right away.
Vulnerabilities & Fixes
- CVE-2026-102255 A pre-authentication server-side request forgery (SSRF) flaw in SonicWall SMA1000 WorkPlace, fixed in hotfix versions 12.4.3-03670 and 12.5.0-03082 or higher. View the fix & details →
- CVE-2026-102256 An OS command injection flaw in SonicWall SMA1000 that requires administrator login and is fixed by the same hotfix. View the fix & details →
- CVE-2026-102257 A Zip Slip flaw in the SMA1000 Appliance Management Console that requires login and is fixed by the same hotfix. View the fix & details →
- CVE-2026-102258 A stored cross-site scripting flaw in the SMA1000 Appliance Management Console that requires administrator login and is fixed by the same hotfix. View the fix & details →
Terms Explained
- SSRF Server-side request forgery, a flaw that lets an attacker trick a server into making requests to internal systems it should not expose.
- CVSS Common Vulnerability Scoring System, a scale from 0 to 10 that measures how serious a security flaw is.
- Pre-authentication Before a user has logged in, meaning an attacker needs no username or password to exploit the flaw.
- SMA1000 SonicWall's line of remote access gateways that allow employees to reach company applications from outside the office.
- WorkPlace The web portal on SMA1000 where users log in to access company resources.
- AMC Appliance Management Console, the administration area where IT staff configure the device.
- XSS Cross-site scripting, a flaw that lets an attacker run harmful scripts in a user's browser after they click a crafted link.