SonicWall Releases Patch for SSRF Vulnerability in SMA 1000 Appliances
SonicWall has resolved four security vulnerabilities impacting its Secure Mobile Access (SMA) 1000 series appliances, including a remotely exploitable server-side request forgery (SSRF) flaw that could enable unauthorized access to internal systems.
Overview of the Vulnerabilities
SonicWall has resolved four security vulnerabilities impacting its Secure Mobile Access (SMA) 1000 series appliances, including a remotely exploitable server-side request forgery (SSRF) flaw that could enable unauthorized access to internal systems. The affected vulnerability, designated CVE-2026-102255, allows unauthenticated attackers to manipulate the appliance into initiating requests to internal resources, potentially bypassing authentication mechanisms.
The SMA 1000 series serves as an SSL VPN gateway for enterprises, managed service providers, and government entities.
Details of the Vulnerabilities
CVE-2026-102255 arises from an unintended alternate access path within the Work Place interface, enabling an unauthenticated attacker to craft requests that force the appliance to interact with internal endpoints. This could facilitate actions typically restricted to authenticated users or administrators. The vulnerability was identified by Benoît Sevens, who also reported CVE-2026-102256, a post-authentication OS command injection flaw. Additional flaws include CVE-2026-102257, a path traversal vulnerability, and CVE-2026-102258, a cross-site scripting issue within the Appliance Management Console. These require administrative authentication to exploit and were disclosed by researcher Brian Mariani.
Affected Models
The affected models span physical and virtual configurations: 6210, 7210, and 8200v.
The SMA 100 Series, which is no longer supported, remains unaffected.
Firmware Updates and Recommendations
SonicWall has released firmware updates to address all four vulnerabilities, recommending users upgrade to versions 12.4.3-03670 or higher, and 12.5.0-03082 or higher. The disclosure follows prior instances where similar vulnerabilities in the SMA 1000 series were exploited as zero-day attacks.
