BlackTree Security · Infrastructure · Automation · AI

The SonicWall Gateway Can Proxy Requests Before Login

SonicWall has fixed four vulnerabilities in SMA1000 models 6210, 7210 and 8200v. The most urgent, CVE-2026-102255, is a pre-authentication server-side request forgery flaw in Appliance WorkPlace. A remote unauthenticated attacker could make the appliance issue requests, reach internal functionality and perform unauthorised operations. SonicWall assigns it a CVSS score of 10.0.

The vendor provides no workaround and says there is currently no evidence that the October vulnerabilities are being exploited. This is an urgent patch advisory, not confirmation of a breach or campaign.

The appliance becomes a confused deputy

The risk is not simply that an outside request reaches the gateway. The gateway can become the intermediary that sends another request from a more trusted position. Controls that assume the appliance is a legitimate source may therefore see the request differently from one arriving directly from the internet.

SonicWall has not published the internal functions or destinations that can be reached in every deployment. The advisory also does not say that the unauthenticated path produces code execution. Defenders should not turn a maximum score into a broader claim than the evidence supports.

Four flaws share one fixed release

  • CVE-2026-102255 is the unauthenticated forward-proxy SSRF.
  • CVE-2026-102256 is operating-system command injection. Under specific conditions, an authenticated administrator can execute arbitrary operating-system commands.
  • CVE-2026-102257 is a post-authentication Zip Slip flaw in the Appliance Management Console that can result in remote code execution.
  • CVE-2026-102258 is stored cross-site scripting. Under specific conditions, an authenticated administrator can store and potentially execute JavaScript in the Appliance Management Console.

SonicWall does not describe a chain between the four flaws. Only the SSRF is pre-authentication. The release should not be presented as unauthenticated remote code execution.

Patch the exact platform-hotfix branch

SMA1000 appliances running 12.4.3-03526 or earlier, or 12.5.0-02952 or earlier, are affected. Fixed releases are 12.4.3-03670 or later and 12.5.0-03082 or later.

The advisory does not apply to the SMA 100 Series or to SSL-VPN running on SonicWall firewalls.

Editorially, defenders should:

  • inventory every 6210, 7210 and 8200v appliance, including dormant recovery systems;
  • verify the complete platform-hotfix version rather than relying on the major release number;
  • install the fixed branch without waiting for KEV or NVD enrichment;
  • restrict management access and review recent administrator, configuration and outbound-request activity; and
  • move into incident response if local evidence indicates that the appliance was accessed or altered.

BlackTree’s earlier SMA1000 article covers different July and September flaws with confirmed exploitation. That history explains why the product deserves fast attention, but it does not establish exploitation of this October set.

Primary source: SonicWall advisory SNWLID-2026-0017, first published and last updated 6 October 2026 at 09:44 UTC.

Leave a Reply

Your email address will not be published. Required fields are marked *