Skip to main content
CybersecurityVulnerability Management

SonicWall Fixes CVSS 10.0 Flaw in SMA1000 Appliances

Network appliance sits on a rack in a data center room with server racks and patch panels.

"reach internal functionality and perform unauthorized operations," SonicWall said in its security advisory, dated October 6.

CVE-2026-102255: a pre-auth SSRF in WorkPlace

SonicWall on October 6 published hotfixes for four vulnerabilities affecting its SMA1000 appliances and identified the most serious as CVE-2026-102255, a server-side request forgery (SSRF) bug in WorkPlace, the portal used by SMA1000 users to log in. According to SonicWall, the issue is reachable before authentication because of "an unintended access path through SonicWall," and an attacker who abuses that path could "reach internal functionality and perform unauthorized operations." SonicWall rated the flaw 10.0 on the CVSS scale and said it has "no evidence that any of the four flaws is being used in attacks."

Affected models and exact firmware windows

All four flaws affect SMA1000 models 6210, 7210 and 8200v when running the listed platform-hotfix versions. Specifically:

  • Version 12.4.3: 12.4.3-03526 and older versions are affected; 12.4.3-03670 and higher versions are fixed.
  • Version 12.5.0: 12.5.0-02952 and older versions are affected; 12.5.0-03082 and higher versions are fixed.

SonicWall noted that the affected versions include 12.4.3-03526 and 12.5.0-02952, which the company identified on September 1 as the fixes for two flaws it had previously reported as exploited—meaning appliances still on those builds require the new hotfix. The hotfix is available through the MySonicWall portal, installation causes the appliance to restart when finished, and SonicWall lists no workaround.

How this fits into SonicWall's 2026 SSRF pattern

This is the third time in 2026 that SonicWall has issued a fix for a 10.0-rated SSRF vulnerability in WorkPlace that requires no login. SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, and CVE-2026-83548 and CVE-2026-83549 on September 1. In its July and September advisories SonicWall said it had investigated attacks exploiting the earlier flaws—"multiple cases" in July and "a case" in September. SonicWall's staff discovered the two earlier pairs; the four new flaws were credited to outside researchers.

Researchers credited and prior exploit details

SonicWall credited Benoît Sevens of Anthropic with reporting CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two reported flaws, with one of those submitted via Trend Micro's Zero Day Initiative. For context, Rapid7 reported that in the July attacks CVE-2026-15409 allowed an attacker with no login to open a tunnel to services that respond only inside the appliance; the attacker could then run commands and use CVE-2026-15410 to gain root access to the appliance. SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way.

What this means for technologists, procurement leaders, and incident teams

  • Technologists and security teams: The hotfix release and the restart requirement are concrete changes to appliance operations—SonicWall made the hotfix available via MySonicWall and stated that installation restarts the appliance and that no workaround is listed. Security teams must match their current SMA1000 firmware against the exact affected builds named by SonicWall.
  • Procurement and enterprise IT leaders: The affected hardware is limited to SMA1000 models 6210, 7210 and 8200v; SonicWall said SSL‑VPN on SonicWall firewalls and the SMA 100 Series are not affected. That delineation will shape patch prioritization and risk assessments for mixed deployments.
  • Incident response and operations teams: SonicWall previously instructed customers—after the July and September disclosures—to check appliances for indicators of compromise and, if found, to re-image or redeploy, change user and administrator passwords, and reset TOTP tokens. SonicWall has given no comparable instruction for the four new flaws.

Five facts stand between customers and action: the CVE identifier (CVE-2026-102255), the 10.0 CVSS rating, the explicit affected models and firmware ranges, the availability of a MySonicWall hotfix that restarts the appliance, and SonicWall's statement that it currently has "no evidence that any of the four flaws is being used in attacks." Whether and how that last assertion holds up will be an immediate question for operators running the vulnerable builds.

For full details and the original advisory, see the Hacker News report: https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html