Critical SonicWall SMA1000 Pre-Authentication SSRF Vulnerability

According to the vendor, the vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote, unauthenticated attacker could exploit the flaw to force the appliance to issue requests on their behalf, potentially reaching internal functionality and performing unauthorized operations.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

The disclosure also included three other post-authentication vulnerabilities affecting the Appliance Management Console (AMC):

  • CVE-2026-102256 is an OS command injection vulnerability that could allow a remote authenticated administrator to execute arbitrary operating system commands, potentially resulting in remote code execution.
  • CVE-2026-102257 is a Zip Slip path traversal vulnerability within the Appliance Management Console. An authenticated attacker could exploit the flaw using a specially crafted archive to extract files outside the intended directory, potentially leading to remote code execution.
  • CVE-2026-102258 is a stored cross-site scripting (XSS) vulnerability that could allow a remote authenticated administrator to store and execute arbitrary JavaScript in the Appliance Management Console.

CVE

CVE-2026-102255
CVE-2026-102256
CVE-2026-102257
CVE-2026-102258

Affected Products

SonicWall SMA1000 Series appliances (6210, 7210, and 8200v) running:
12.4.3-03526 and earlier versions
12.5.0-02952 and earlier versions

Exploitation

There is currently no evidence of this vulnerability being exploited in the wild.

Recommended Actions

Truesec recommends upgrading to the latest versions to remediate the patch.

Latest versions:
For vulnerable version 12.4.3-03526 – Upgrade to versions 12.4.3-03670 or later
For vulnerable version 12.5.0-02952 – Upgrade to version 12.5.0-03082 or later

The post Critical SonicWall SMA1000 Pre-Authentication SSRF Vulnerability appeared first on Truesec.

Article Link: Critical SonicWall SMA1000 Pre-Authentication SSRF Vulnerability - Truesec