thehackernews.com 7 Oct 2026, 16:17 UTC

SonicWall fixes pre-auth flaw rated 10.0 in SMA1000 appliances

SONICWALL has released hotfixes for four high‑impact flaws in its SMA1000 appliances, including a pre‑authentication server‑side request forgery (SSRF) rated 10.0 on the CVSS scale. The most serious flaw, CVE-2026-102255, affects WorkPlace and can be reached before authentication, allowing an attacker to reach internal functionality and perform unauthorized operations. SonicWall reports no evidence of active exploitation at this time.

The other three flaws require some form of access or login to be exploited, including CVE-2026-102256 (OS command injection), CVE-2026-102257 (Zip Slip), and CVE-2026-102258 (stored XSS) with varying impact.

The issues affect SMA1000 models 6210, 7210 and 8200v running platform hotfix versions 12.4.3 and 12.5.0. Specifically, 12.4.3: 12.4.3-03526 and older are affected; fixed in 12.4.3-03670 and newer. 12.5.0: 12.5.0-02952 and older are affected; fixed in 12.5.0-03082 and newer. Notably, SSL‑VPN on SonicWall firewalls and the SMA 1000 Series are not affected. The hotfix is available via the MySonicWall portal and requires an appliance restart after installation; no workaround is listed.

Researchers Benoît Sevens and Brian Mariani were credited for the reported flaws, with the SSRF flaw highlighted as the third 10.0‑rated pre‑authentication issue SonicWall has disclosed this year.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline