← Back to CVE List
Vulnerability Intelligence Report

CVE-2026-102255

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-918 ↗CWE-918 Server-Side request forgery (SSRF)
CWE-441 ↗CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')

Affected Products & Versions

Vendor Product Affected Versions
SonicWall SMA1000 12.4.3-03526 (platform-hotfix) and older versions (affected), 12.5.0-02952 (platform-hotfix) and older versions (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySonicWall, Inc. · Vendor · USA
Reserved2026-09-28T19:39:42
Published2026-10-07T13:07:13
Patch Date2026-10-07
Last Updated2026-10-07T15:51:00

LINK COPIED TO CLIPBOARD