News · Science & Technology
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
The affected products are SonicWall SMA1000 appliances, specifically models 6210, 7210, and 8200v. The four flaws affect two platform-hotfix branches. This matters because these appliances provide remote workers access to company networks and applications. For version 12.4.3, releases 12.4.3-03526 and earlier are affected. Version 12.4.3-03670 and later fix the flaws. For version 12.5.0, releases 12.5.0-02952 and earlier are affected, while 12.5.0-03082 and later are fixed. SonicWall says 12.4.3-03526 and 12.5.0-02952 were previously named fixes for two flaws reported as exploited. Appliances still running either release therefore need the new hotfix. SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.
Based on reporting by The Hacker News
Which SonicWall SMA1000 appliances and software versions are affected, and what hotfix versions fix the flaws?
The affected products are SonicWall SMA1000 appliances, specifically models 6210, 7210, and 8200v. The four flaws affect two platform-hotfix branches. This matters because these appliances provide remote workers access to company networks and applications.
For version 12.4.3, releases 12.4.3-03526 and earlier are affected. Version 12.4.3-03670 and later fix the flaws. For version 12.5.0, releases 12.5.0-02952 and earlier are affected, while 12.5.0-03082 and later are fixed.
SonicWall says 12.4.3-03526 and 12.5.0-02952 were previously named fixes for two flaws reported as exploited. Appliances still running either release therefore need the new hotfix. SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.
What is server-side request forgery (SSRF), and why is this flaw especially serious when it can be used before authentication?
Server-side request forgery, or SSRF, occurs when an attacker makes a server send requests on the attacker’s behalf. The server may be able to reach internal services or functions that are not directly exposed to the internet. That turns the trusted appliance into a pathway toward protected areas.
CVE-2026-102255 is an SSRF flaw in WorkPlace, the SMA1000 portal used by customers to log in. SonicWall says an unintended access path lets an attacker reach it before authentication. The attacker could send requests through the appliance and reach internal functionality.
The pre-authentication aspect removes the normal login barrier. SonicWall rates the flaw 10.0 on the CVSS scale, the highest severity rating. The company has not identified the exact internal functions involved and says it has no evidence that this particular flaw is being exploited.
How could an unauthenticated attacker use the unintended access path to reach internal functionality and perform unauthorized operations?
The core risk is that WorkPlace exposes an unintended route through the SMA1000 appliance. Normally, a remote user must authenticate before reaching protected portal functions. This flaw lets an attacker reach the route first, so the appliance may process requests from someone who has no account or session.
The practical example is CVE-2026-102255. An attacker sends a crafted request to the exposed WorkPlace path. The appliance then handles that request internally, allowing the attacker to reach internal functionality and perform unauthorized operations, according to SonicWall’s advisory.
The article does not specify which functions or operations are available. SonicWall also has not said whether this new SSRF flaw can be combined with the other three vulnerabilities. The other three require login, so the exact attack chain and resulting impact remain undisclosed.
What does a CVSS score of 10.0 mean, and how severe is that rating compared with other software vulnerabilities?
CVSS, the Common Vulnerability Scoring System, rates the technical severity of software vulnerabilities on a scale from 0.0 to 10.0. A score of 10.0 is the maximum possible rating. It indicates an exceptionally serious combination of factors, such as remote reachability, low attack barriers, and potentially major impact.
CVE-2026-102255 receives that maximum score because it is a pre-authentication SSRF flaw in a remote-access gateway. An attacker does not need a login to reach the unintended path. SonicWall says the path could expose internal functionality and allow unauthorized operations.
Compared with other vulnerabilities, 10.0 is the top rating rather than an average high score. CVSS measures severity, not proof that attacks are occurring. SonicWall says it has no evidence that any of these four flaws is being used in attacks, even though the leading flaw is rated 10.0.
What should organizations do if their SMA1000 appliance is still on an affected version, and what happens when the hotfix is installed?
Organizations should first determine whether their SMA1000 appliance is running an affected release. Versions 12.4.3-03526 and earlier, or 12.5.0-02952 and earlier, need the new hotfix. This includes releases SonicWall previously identified as fixes for two flaws reported as exploited.
The hotfix is available through the MySonicWall portal. Administrators should apply the matching fixed release: 12.4.3-03670 or later for the 12.4.3 branch, and 12.5.0-03082 or later for the 12.5.0 branch. SonicWall lists no workaround.
The appliance restarts when installation finishes, so organizations should plan for that interruption. SonicWall gives no instruction to re-image appliances, change passwords, or reset TOTP tokens for these four new flaws. Those steps appeared in earlier advisories when indicators of compromise were found.
Why is it notable that SonicWall has fixed three separate 10.0-rated, pre-authentication SSRF flaws in the WorkPlace portal in one year?
The pattern matters because WorkPlace has produced three separate 10.0-rated SSRF flaws requiring no login in one year. SonicWall disclosed the first pair on July 14, the second pair on September 1, and the latest four flaws in an advisory dated October 6. Repeated high-severity findings show continuing risk around this remote-access portal.
The earlier SSRF flaws were CVE-2026-15409 and CVE-2026-83548. SonicWall said it investigated “multiple cases” exploiting the July flaw and “a case” involving the September flaw. In July, Rapid7 reported that attackers used the flaw to tunnel to internal services.
SonicWall’s staff found the earlier pairs, while outside researchers found the new four flaws. The latest advisory says there is no evidence of attacks using the new flaws. SonicWall has not said whether the new SSRF can be combined with the other three vulnerabilities.
Why are internet-facing remote-access gateways attractive targets, and how do authentication boundaries normally protect the internal services behind them?
Internet-facing remote-access gateways are attractive targets because they provide a doorway for remote workers into company networks and applications. A weakness in that doorway can offer access to functions that would otherwise be difficult to reach. The SMA1000 appliances described here serve exactly that gateway role.
Authentication normally creates the boundary. A user reaches the public portal, proves their identity, and only then receives access to authorized services. Internal functions remain behind that login requirement. An SSRF flaw can weaken the boundary by making the gateway send requests internally before the requester has authenticated.
That is why the WorkPlace flaw matters even though SonicWall has not identified the exact functions involved. CVE-2026-102255 allows access through an unintended path before login. The other three new flaws require authentication, and SonicWall has not said whether attackers can combine them with the new SSRF.
Key Facts:
📌 Affected models are SMA1000 6210, 7210, and 8200v.
📌 12.4.3-03670 and later versions fix the flaws.
📌 12.5.0-03082 and later versions fix the flaws.
📌 SSRF makes a server send requests on an attacker’s behalf.
📌 CVE-2026-102255 is reachable before authentication.
📌 SonicWall rates the flaw 10.0 on CVSS.
📌 The unintended path is reachable before authentication.