Critical Pre‑Auth SSRF Vulnerability (CVE‑2026‑102255) in SonicWall SMA1000 Appliances
What It Is – SonicWall disclosed a pre‑authentication Server‑Side Request Forgery (SSRF) flaw in the WorkPlace portal of its SMA1000 remote‑access appliances. The vulnerability (CVE‑2026‑102255) carries a CVSS 10.0 rating, meaning an unauthenticated attacker could direct the appliance to issue arbitrary internal requests and perform unauthorized operations.
Exploitability – No public exploitation has been observed, but the flaw is trivial to weaponize once a vulnerable version is reachable. A vendor‑issued hotfix is available; no workaround exists.
Affected Products – SMA1000 models 6210, 7210, 8200v running firmware 12.4.3‑03526 (or older) and 12.5.0‑02952 (or older). Other SMA‑100 series products and SSL‑VPN functionality are not impacted.
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous verification that unauthenticated traffic cannot reach internal management functions – a core access‑control assurance objective.
- Demonstrates how a single unpatched flaw can break the audit trail of “defensible evidence” that an organization’s perimeter controls are effective.
- Provides a concrete control‑gap example that can be mapped to multiple frameworks (e.g., NIST CSF PR.AC‑1) to show remediation readiness to enterprise buyers.
Recommended Actions
- Deploy the SonicWall SMA1000 hotfixes immediately via the MySonicWall portal.
- Conduct post‑patch testing to confirm the WorkPlace portal no longer accepts unauthenticated SSRF requests.
- Update your control inventory, capture remediation evidence, and align the fix with your framework of record for audit readiness.
Source: SecurityAffairs article