we_are_coded.by CODE · The world, decoded
БГ
SonicWall

SonicWall patches an unauthenticated 10.0 hole in SMA1000, with no evidence of exploitation so far

SonicWall PSIRT (CVE-2026-102255, CVE-2026-102256, CVE-2026-102257) · event date: 6 October 2026Security

On 6 October SonicWall published an advisory on four vulnerabilities in the SMA1000. The first, CVE-2026-102255, is an unauthenticated SSRF rated 10.0. SonicWall says there is no evidence of exploitation, and none of them are listed in CISA's catalog.

In short
  • 6 October 2026: SonicWall patched four vulnerabilities in the SMA1000 series (SNWLID-2026-0017). The first, CVE-2026-102255, is an unauthenticated SSRF in the Work Place interface, rated 10.0.
  • Affected: 6210, 7210 and 8200v on 12.4.3-03526 and older or 12.5.0-02952 and older. Fix: 12.4.3-03670 and 12.5.0-03082 and newer, with no workaround. SSL-VPN on firewalls and the SMA 100 are not affected.
  • SonicWall says there is no evidence of exploitation; none of the four is listed in CISA's KEV catalog (checked on 9 October). In our articles this is the third unauthenticated 10.0 hole in the SMA1000 since July; CISA listed the first two as exploited.
Checked on9 October 2026Responsible editorCvetelin IvanovHow we workMethod · Corrections

For the third time since July, we are writing about an unauthenticated hole in the SonicWall SMA1000 rated 10.0. The first two went into CISA's catalog of actively exploited vulnerabilities. This one has not.

The facts: on 6 October 2026 SonicWall published advisory SNWLID-2026-0017 on four vulnerabilities in the SMA1000 series. CVE-2026-102255 is a pre-authentication SSRF in the Work Place interface: because of an "unintended alternate access path", a remote attacker with no login can make the appliance send requests on their behalf and reach internal functionality. SonicWall rates it 10.0 on CVSS (vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); NVD shows the same 10.0, with the score there coming from CISA-ADP while NVD's own assessment is not yet provided. CVE-2026-102256 is an OS command injection after logging in as an administrator, which can lead to remote code execution. CVE-2026-102257 is a Zip Slip in the appliance management console (AMC), also after login and also leading to code execution. The fourth vulnerability is a stored XSS in the AMC, again after login. Affected are models 6210, 7210 and 8200v running versions 12.4.3-03526 and older or 12.5.0-02952 and older (platform-hotfix). The fix is in versions 12.4.3-03670 and 12.5.0-03082 (platform-hotfix) and newer, downloadable from mysonicwall.com; there is no workaround. SonicWall says there is currently no evidence that these vulnerabilities are being exploited in the wild. The advisory explicitly excludes SSL-VPN on SonicWall firewalls and the SMA 100 product line. In the credits, SonicWall names Benoît Sevens of Anthropic for the first two CVEs; the other two were reported by Brian Mariani. None of the four is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, we checked on 9 October.

The difference from the previous two is the order. This time the patch comes first, and SonicWall says there is no evidence of attacks. If that holds, the lead is yours.

Mind the words: "no evidence" is not "no exploitation". For a hole you can reach without logging in, the gap is large. How much time you have left, nobody knows.

Every day the hotfix is not installed, the lead shrinks.

Compare your SMA1000's version with 12.4.3-03670 and 12.5.0-03082. If it is older, the hotfix is on mysonicwall.com, and there is no workaround.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→SonicWall PSIRT (CVE-2026-102255, CVE-2026-102256, CVE-2026-102257) - SNWLID-2026-0017, 06.10.2026→NVD (CVE-2026-102255), record as of 09.10.2026→CVE.org (CVE-2026-102255), record as of 09.10.2026→CISA - Known Exploited Vulnerabilities Catalog (version 2026.10.08), checked 09.10.2026
Original: https://wearecoded.com/en/articles/sonicwall-sma1000-cve-2026-102255-ssrf-treti-pat.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news