SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.
Intelligence analysis by Qwen 2.5 (3B)

SonicWall has patched a critical security flaw in its SMA1000 appliances, which could allow attackers to bypass authentication and access internal functions.
SonicWall fixed a big security problem in their appliances that could let bad guys trick the system into doing things they shouldn't. They patched four different problems to keep the appliances safe.
Analysis
{"#server-side-request-forgery":"The most serious flaw, CVE-2026-102255, is a server-side request forgery (SSRF) bug in WorkPlace, the portal used by SMA1000 users to log in. This flaw allows attackers to bypass authentication and reach internal functions.","#os-command-injection":"CVE-2026-102256 is an OS command injection flaw in the SMA1000 appliance, which could lead to remote code execution. This flaw affects the SMA1000 appliance, but not the SSL-VPN on SonicWall firewalls or the SMA 100 Series.","#zip-slip":"CVE-2026-102257 is a zip slip vulnerability in the Appliance Management Console (AMC), which could allow attackers to extract files outside the intended folder and lead to remote code execution. This flaw affects the AMC login.","#stored-cross-site-scripting":"CVE-2026-102258 is a stored cross-site scripting (XSS) flaw in the AMC, which could allow attackers to inject malicious scripts into the appliance. This flaw affects the AMC administrator login."}
Key points
- SonicWall patched four security flaws in its SMA1000 appliances
- The most serious flaw is a server-side request forgery (SSRF) bug in WorkPlace
- The vulnerabilities could allow attackers to bypass authentication and access internal functions
- The patch is available from the MySonicWall portal and the appliance restarts after installation
- No workaround is listed for the vulnerabilities
The patch should help keep attackers from using the vulnerabilities to cause trouble. It's a good step to protect the appliances and the networks they're used in.
Even with the patch, the vulnerabilities could still be used in the future. SonicWall needs to continue monitoring and updating their appliances to stay secure.



