SonicWall has issued critical updates to address multiple security vulnerabilities within its SMA1000 appliances, devices that facilitate remote access to corporate networks. Among these, a particularly severe flaw could potentially allow unauthorized users to exploit the system, posing significant security risks.
Details of the Vulnerability
The most pressing issue, identified as CVE-2026-102255, is a server-side request forgery (SSRF) vulnerability within the WorkPlace portal of the SMA1000. This flaw is particularly concerning as it can be exploited prior to user authentication, enabling attackers to execute unauthorized actions within the system.
According to SonicWall’s advisory, published on October 6, the vulnerability has been rated a maximum score of 10.0 on the CVSS scale, indicating its critical nature. Despite the severity, SonicWall reports no known instances of this flaw being exploited in real-world attacks.
Affected Models and Versions
The vulnerabilities impact several SMA1000 models, including 6210, 7210, and 8200v. Specific versions affected are 12.4.3-03526 and earlier, and 12.5.0-02952 and earlier. SonicWall has released fixes, with versions 12.4.3-03670 and 12.5.0-03082 addressing the issues.
Devices still operating on the vulnerable versions must urgently apply the new hotfixes available through the MySonicWall portal. Notably, these flaws do not impact SSL-VPN on SonicWall firewalls or the SMA 100 Series.
Additional Vulnerabilities and Fixes
The security update also addresses three other vulnerabilities that require authentication for exploitation. These include an OS command injection vulnerability (CVE-2026-102256), a Zip Slip vulnerability (CVE-2026-102257), and a stored cross-site scripting flaw (CVE-2026-102258). The latter two specifically affect the Appliance Management Console (AMC).
Previous instances in July and September saw similar SSRF vulnerabilities, but SonicWall’s latest advisories do not suggest these can be combined with the current flaws in a similar manner. The company has credited external researchers for identifying the new vulnerabilities, emphasizing a collaborative approach to cybersecurity.
Going forward, SonicWall recommends continuous monitoring for signs of compromise and suggests regular security updates to mitigate potential threats. As the cybersecurity landscape evolves, such proactive measures remain crucial in protecting network integrity.
