SonicWall fixes SSRF flaw rated 10.0 in SMA1000 remote access gateways
SonicWall has issued hotfixes for four SMA1000 flaws, led by a server-side request forgery bug that needs no login and that it scores 10.0. The company says it has seen no exploitation so far.

Key points
- 1SonicWall rates CVE-2026-102255, an SSRF flaw in the SMA1000 WorkPlace portal that needs no login, 10.0 on the CVSS scale.
- 2The hotfixes cover four flaws on SMA1000 models 6210, 7210 and 8200v; fixed builds are 12.4.3-03670 and 12.5.0-03082 or later.
- 3SonicWall says it has seen no exploitation of any of the four flaws so far.
- 4According to The Hacker News, the builds SonicWall named as fixes on September 1 are among the affected versions.
- 5The SMA 100 Series and the SSL-VPN feature on SonicWall firewalls are not affected.
Full story
SonicWall has released hotfixes for four vulnerabilities in its SMA1000 series, the appliances companies use to give remote staff access to internal networks and applications, The Hacker News and BleepingComputer report. The most severe, CVE-2026-102255, is a server-side request forgery (SSRF) flaw in the WorkPlace portal that can be reached without logging in. SonicWall gives it a CVSS score of 10.0, the top of the scale. In its advisory, which The Hacker News dates to October 6, the company says an unauthenticated remote attacker could abuse an unintended access path to make the appliance send requests for them, reach internal functions and carry out unauthorized operations. The advisory does not say which functions are exposed.
According to SonicWall, there is so far no sign of attackers using any of the four flaws, and the company advises SMA1000 customers to move to the fixed releases. The affected models are the SMA1000 6210, 7210 and 8200v. According to The Hacker News, builds up to 12.4.3-03526 on the 12.4.3 branch are vulnerable and 12.4.3-03670 or later carries the fix; on the 12.5.0 branch, builds up to 12.5.0-02952 are vulnerable and 12.5.0-03082 or later is fixed. Neither the SMA 100 Series nor the SSL-VPN feature on SonicWall firewalls is affected. The Hacker News adds that the hotfix is distributed through the MySonicWall portal, that the appliance reboots once it is installed, and that no workaround is listed.
The other three flaws can only be used after logging in. CVE-2026-102256 is an OS command injection that needs administrator access and could lead to remote code execution; SonicWall scores it 7.8, according to The Hacker News. CVE-2026-102257, rated 7.2, is a Zip Slip flaw in the Appliance Management Console (AMC): a crafted archive can place files outside the folder it is meant to unpack into, which could also end in remote code execution. CVE-2026-102258, rated 5.5, is a stored cross-site scripting flaw in the AMC that requires an administrator account. The Hacker News reports that SonicWall credited outside researchers this time: CVE-2026-102255 and CVE-2026-102256 were reported by Benoît Sevens of Anthropic, while Brian Mariani of DigitalCanion SA found the remaining two, one of them submitted via Trend Micro's Zero Day Initiative.
The fix lands after a series of exploited SMA1000 bugs. By The Hacker News' count, this is the third WorkPlace SSRF flaw rated 10.0 and reachable without a login that SonicWall has patched this year: the earlier pairs were CVE-2026-15409 with CVE-2026-15410, made public on July 14, and CVE-2026-83548 with CVE-2026-83549, made public on September 1, and in both cases SonicWall said it had investigated attacks using them. BleepingComputer reports that the July pair was exploited for weeks to install Sou5, OrangeTail and RootRun malware, in attacks CISA tied to ransomware gangs. The Hacker News also points out that the vulnerable builds include 12.4.3-03526 and 12.5.0-02952, the builds that SonicWall pointed to on September 1 as fixing the exploited pair, so appliances updated at that point still need the new hotfix. According to the same outlet, SonicWall has not stated if the new SSRF bug can be chained with the other three, and it has not repeated its earlier advice to check appliances for indicators of compromise.
Why it matters
SMA1000 gateways sit at the edge of corporate networks and, according to BleepingComputer, are used by government agencies, managed service providers and large companies, which makes them a frequent target. BleepingComputer cites Shadowserver as tracking more than 400 SMA1000 appliances reachable from the internet, some of which may already be patched, and reports that CISA has listed 19 SonicWall flaws as actively exploited over the past four years, 13 of them in ransomware attacks. SonicWall reports no exploitation of the new flaws so far, but appliances that took the September fix remain vulnerable until the new hotfix is installed.
Timeline
· Published
Topics#SonicWall#SMA1000#SSRF#vulnerability#remote access
Sources
This story draws on the following sources. Read them for full context.



