Vulnerability Intelligence Report
CVE-2026-102255
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-918 ↗CWE-918 Server-Side request forgery (SSRF)
CWE-441 ↗CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SonicWall | SMA1000 | 12.4.3-03526 (platform-hotfix) and older versions (affected), 12.5.0-02952 (platform-hotfix) and older versions (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SonicWall, Inc. · Vendor · USA |
| Reserved | 2026-09-28T19:39:42 |
| Published | 2026-10-07T13:07:13 |
| Patch Date | 2026-10-07 |
| Last Updated | 2026-10-07T15:51:00 |
Community Chatter & Buzz