Ethical Hacking News
SonicWall has released hotfixes to address four critical vulnerabilities in its SMA1000 appliances, including a 10.0-CVSS pre-authentication SSRF flaw. The most serious flaw, tracked as CVE-2026-102255, can be exploited by an attacker without a login, allowing them to reach internal functions and perform unauthorized operations.
SonicWall has released hotfixes to address four critical vulnerabilities in its SMA1000 appliances, including a server-side request forgery (SSRF) bug. The SSRF bug can be exploited by an attacker without a login, allowing them to reach internal functions and perform unauthorized operations. The four vulnerabilities affect SMA1000 models 6210, 7210, and 8200v on specific platform-hotfix versions. SonicWall has credited outside researchers with the discovery of the bugs, including Benoît Sevens and Brian Mariani. The company has stated that it has no evidence that any of the four flaws is being used in attacks, but its own staff found the bugs. Customers are advised to check their appliances for indicators of compromise and, if found, to re-image or redeploy the appliance, change user and administrator passwords, and reset TOTP tokens. No instructions have been given for the four new flaws, leaving customers with no clear workaround.
SonicWall, a leading manufacturer of network security appliances, has recently released hotfixes to address four critical vulnerabilities in its SMA1000 appliances. The most serious of these flaws, tracked as CVE-2026-102255, is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to. This flaw is particularly concerning as it can be exploited by an attacker without a login, allowing them to reach internal functions and perform unauthorized operations.
According to SonicWall, the 10.0-CVSS-rated SSRF flaw exists due to an unintended access path through the SonicWall and can be reached before authentication. This means that even without a login, an attacker can potentially abuse this path to access internal functionality. SonicWall has stated that it has no evidence that any of the four flaws is being used in attacks, but the company's own staff found the bugs, which were reported by outside researchers.
The four vulnerabilities affect SMA1000 models 6210, 7210, and 8200v on specific platform-hotfix versions. For these models, version 12.4.3 is affected by the 03526 and older versions, while version 12.5.0 is affected by the 02952 and older versions. In contrast, versions 12.4.3-03670 and higher, and 12.5.0-03082 and higher, are fixed.
It is worth noting that SonicWall has previously disclosed two other 10.0-CVSS-rated SSRF flaws in WorkPlace, which were discovered by the company's own staff and outside researchers. These flaws were found in July and September advisories, and SonicWall credited outside researchers with the discovery of the new bugs.
In its latest advisory, SonicWall has advised customers to check their appliances for indicators of compromise and, if any were found, to re-image or redeploy the appliance, change user and administrator passwords, and reset the TOTP tokens used for one-time login codes. However, for the four new flaws, no such instructions have been given.
The affected versions include 12.4.3-03526 and 12.5.0-02952, which SonicWall named on September 1 as the fix for two flaws it reported as exploited. An appliance still on those versions needs the new hotfix. The hotfix is available from the MySonicWall portal, and the appliance restarts when the installation finishes. No workaround is listed.
The other three flaws can be used only after logging in. Two of them are in the Appliance Management Console (AMC), where administrators configure the appliance. The flaws include an OS command injection that could lead to remote code execution, a zip slip bug that could allow an attacker to extract files outside the intended folder, which could lead to remote code execution, and a stored cross-site scripting (XSS) bug in the AMC.
SonicWall has disclosed the four new flaws in its security advisory, dated October 6. The company has credited outside researchers with the discovery of the bugs, including Benoît Sevens of Anthropic for CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two. SonicWall has stated that it has no evidence that any of the four flaws is being used in attacks, but the company's own staff found the bugs.
In the July attacks, CVE-2026-15409 allowed an attacker with no login to open a tunnel to services that respond only inside the appliance, according to Rapid7. The attacker could then run commands and use CVE-2026-15410 to gain root access, which is full control of the appliance. SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way.
SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way. In its July and September advisories, SonicWall told customers to check their appliances for indicators of compromise and, if any were found, to re-image or redeploy the appliance, change user and administrator passwords, and reset the TOTP tokens used for one-time login codes. However, for the four new flaws, no such instructions have been given.
The hotfix is available from the MySonicWall portal, and the appliance restarts when the installation finishes. No workaround is listed.
The other three flaws can be used only after logging in. Two of them are in the Appliance Management Console (AMC), where administrators configure the appliance. The flaws include an OS command injection that could lead to remote code execution, a zip slip bug that could allow an attacker to extract files outside the intended folder, which could lead to remote code execution, and a stored cross-site scripting (XSS) bug in the AMC.
SonicWall has disclosed the four new flaws in its security advisory, dated October 6. The company has credited outside researchers with the discovery of the bugs, including Benoît Sevens of Anthropic for CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two. SonicWall has stated that it has no evidence that any of the four flaws is being used in attacks, but the company's own staff found the bugs.
In the July attacks, CVE-2026-15409 allowed an attacker with no login to open a tunnel to services that respond only inside the appliance, according to Rapid7. The attacker could then run commands and use CVE-2026-15410 to gain root access, which is full control of the appliance. SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way.
In conclusion, SonicWall has addressed four critical vulnerabilities in its SMA1000 appliances, including a 10.0-CVSS pre-authentication SSRF flaw. The company has credited outside researchers with the discovery of the bugs and has stated that it has no evidence that any of the four flaws is being used in attacks. However, the company's own staff found the bugs, which were previously reported as exploited in July and September advisories. SonicWall has advised customers to check their appliances for indicators of compromise and, if any were found, to re-image or redeploy the appliance, change user and administrator passwords, and reset the TOTP tokens used for one-time login codes. However, for the four new flaws, no such instructions have been given.
Related Information:
https://www.ethicalhackingnews.com/articles/SonicWall-Addresses-Four-Critical-Vulnerabilities-in-SMA1000-Appliances-Including-a-100-CVSS-Pre-Authentication-SSRF-Flaw-ehn.shtml
https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html
Published: Wed Oct 7 14:40:08 2026 by llama3.2 3B Q4_K_M