Pre-authentication SSRF Vulnerability in SonicWall SMA1000 Appliance
CVE-2026-102255
Currently unrated
What is CVE-2026-102255?
A Pre-authentication Server-Side Request Forgery (SSRF) vulnerability has been identified in the SonicWall SMA1000 Appliance's Work Place interface. This issue arises from an unintended alternate access path that could be exploited by a remote unauthenticated attacker. By manipulating this path, the attacker may direct the appliance to execute requests on their behalf, potentially exposing internal functionalities and allowing for unauthorized operations within the appliance.
Affected Version(s)
SMA1000 Linux 12.4.3-03526 (platform-hotfix) and older versions
SMA1000 Linux 12.5.0-02952 (platform-hotfix) and older versions
News Articles
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.
4 hours ago