SonicWall has recently issued patches for four significant vulnerabilities found in its Secure Mobile Access (SMA) 1000 Series appliances. Among these, a critical server-side request forgery (SSRF) flaw has been identified, which holds a perfect CVSS score of 10.0, indicating its severity. This flaw could permit an unauthorized remote user to manipulate the appliance into making requests on their behalf, thereby accessing internal functions and executing unauthorized actions.
Details of the Critical SSRF Flaw
The most severe of these vulnerabilities, tracked as CVE-2026-102255, affects the SMA1000 Appliance WorkPlace interface. It arises from an unintended alternate access pathway, enabling the device to function as a forward proxy. This vulnerability is particularly alarming as it allows attackers to exploit the appliance without any need for authentication or user manipulation, potentially impacting the confidentiality, integrity, and availability of the system. SonicWall categorizes this flaw under CWE-918 for SSRF and CWE-441 for an unintended proxy, often referred to as a confused deputy issue.
Additional Vulnerabilities and Their Implications
In addition to the SSRF flaw, SonicWall has addressed several other vulnerabilities. CVE-2026-102256, with a CVSS rating of 7.8, is a post-authentication command injection vulnerability that could allow an authenticated administrator to execute arbitrary system commands, potentially leading to remote code execution. Another flaw, CVE-2026-102257, rated 7.2, is a Zip Slip vulnerability in the Appliance Management Console (AMC), which could result in files being extracted outside their intended directory, posing a risk of remote code execution.
The fourth vulnerability, CVE-2026-102258, involves stored cross-site scripting (XSS) in the AMC with a CVSS score of 5.5. Under certain conditions, this could enable an authenticated administrator to store and execute arbitrary JavaScript within the management console.
Security Updates and Recommendations
SonicWall has released security advisory SNWLID-2026-0017, urging users to apply the necessary software updates to safeguard against these vulnerabilities. Affected versions include 12.4.3-03526 and earlier, and 12.5.0-02952 and earlier. Users are advised to update to platform-hotfix 12.4.3-03670 or later, or 12.5.0-03082 or later, based on their software branch. The updates are available through MySonicWall, and there are no workarounds for these issues.
It is important to note that SSL-VPN services on SonicWall firewalls and the SMA 100 Series product line are not impacted by these vulnerabilities. This differentiation aids administrators in identifying and updating only the affected devices.
Previously, SonicWall had reported other SMA1000 vulnerabilities, CVE-2026-83548 and CVE-2026-83549, which were actively exploited. However, the current advisory highlights new issues that require immediate attention despite any prior updates. Administrators should verify their systems against the latest patched versions to ensure comprehensive security.
Stay informed and protect your networks by integrating SonicWall’s latest updates and maintaining vigilance against potential cyber threats.
