SonicWall has released hotfixes for a serious server-side request forgery (SSRF) vulnerability in its SMA 1000 series appliances. The two sources agree on the core issue: one rates it maximum severity, while the other identifies it as CVE-2026-102255, a pre-authentication flaw in the SMA 1000 Work Place interface.
The vulnerability stems from an unintended alternate access path that lets an unauthenticated attacker trick the appliance into making requests to internal endpoints, potentially performing actions reserved for logged-in users or administrators. The vendor says there is no evidence of active exploitation, but similar pre-auth SSRF flaws in these appliances were leveraged as zero-days earlier in 2026.
The update addresses four vulnerabilities total, including a post-authentication OS command injection, a path traversal, and a cross-site scripting issue in the Appliance Management Console. Patches apply to SMA 1000 models 6210, 7210, and 8200v; users should upgrade to firmware 12.4.3-03670 or 12.5.0-03082 and higher. Firewall products and the older SMA 100 series are not affected.