VYPR
patchPublished Oct 7, 2026· 1 source

SonicWall SMA 1000 Appliances Vulnerable to Pre-Auth SSRF Flaw

SonicWall has released patches for four vulnerabilities affecting its SMA 1000 series appliances, including a critical pre-authentication Server-Side Request Forgery (SSRF) flaw.

SonicWall has issued critical security updates for its Secure Mobile Access (SMA) 1000 series appliances, addressing a total of four vulnerabilities. The most significant among these is CVE-2026-102255, a pre-authentication Server-Side Request Forgery (SSRF) vulnerability that poses a considerable risk to organizations utilizing these devices.

This SSRF flaw allows unauthenticated remote attackers to exploit an unintended alternate access path within the Appliance Work Place interface. By sending a crafted request, an attacker can compel the SMA appliance to issue requests on their behalf to internal systems or services that trust the appliance. This could enable attackers to access internal functionality and perform unauthorized operations that would otherwise require proper authentication.

While SonicWall has stated there is currently no evidence of these vulnerabilities being exploited in the wild, the vendor has cautioned that exploitation is a distinct possibility given the nature of the flaws and the historical targeting of SonicWall SMA appliances. Previous attacks have leveraged similar pre-authentication SSRF vulnerabilities in SMA 1000 series devices as zero-days, highlighting the importance of prompt patching.

The vulnerabilities affect physical and virtual models of the SMA 1000 series, specifically the 6210, 7210, and 8200v appliances. The company has provided specific firmware hotfix versions for customers to upgrade to: 12.4.3-03670 and higher, and 12.5.0-03082 and higher.

In addition to the critical SSRF vulnerability, SonicWall also patched CVE-2026-102256, a post-authentication OS command injection flaw. Two other vulnerabilities, CVE-2026-102257 (path traversal) and CVE-2026-102258 (cross-site scripting), were also addressed. These latter two vulnerabilities require an attacker to be already authenticated as an administrator to be exploited.

Researchers Benoît Sevens and Brian Mariani are credited with reporting CVE-2026-102255 and CVE-2026-102256, and CVE-2026-102257 and CVE-2026-102258 respectively. The fixes are available for the SMA 1000 series, and SonicWall has confirmed that its firewall products and the discontinued SMA 100 Series are not affected by these particular issues.

Organizations using SonicWall SMA 1000 appliances are strongly advised to apply the available patches immediately to mitigate the risk of exploitation. The potential for attackers to gain unauthorized access to internal networks via this SSRF vulnerability underscores the ongoing need for diligent vulnerability management and timely security updates.

Synthesized by Vypr AI