Back to vendor advisories
SonicWall PSIRT AdvisoriesSNWLID-2026-0017

SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities

1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations. CVSS Score: 10.0 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-918: Server-Side Request Forgery (SSRF) CWE-441: Unintended Proxy or Intermediary ('Confused Deputy') 2) CVE-2026-102256 - Post-authentication Remote Code Execution (RCE) Vulnerability Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. CVSS Score: 7.8 CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3) CVE-2026-102257 - Post-authentication Zip Slip Vulnerability A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution. CVSS Score: 7.2 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4) CVE-2026-102258 - Post-authentication Stored Cross-Site Scripting (XSS) Vulnerability Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC). CVSS Score: 5.5 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') SonicWall strongly advises users of the SMA1000 series appliances to upgrade to the mentioned fixed release versio

10.0CVSS out of 10Critical severity
Scope

What the vendor says is affected

  • SMA1000 Models - 6210, 7210, 8200v: 12.4.3-03526 (platform-hotfix) and older versions. 12.5.0-02952 (platform-hotfix) and older versions.

Versions the vendor lists as fixed

  • SMA1000 Models - 6210, 7210, 8200v: 12.4.3-03670 (platform-hotfix) and higher versions. 12.5.0-03082 (platform-hotfix) and higher versions.
Next step

What the vendor recommends

Install the applicable fixed SonicWall release for your product and branch. SMA1000 Models - 6210, 7210, 8200v: 12.4.3-03670 (platform-hotfix) and higher versions. 12.5.0-03082 (platform-hotfix) and higher versions.

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by SonicWall

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory