SonicWall patches critical 10.0 flaw in SMA1000 appliances
SonicWall disclosed CVE-2026-102255, a pre-authentication SSRF rated 10.0 on CVSS in the SMA1000 Appliance Work Place interface, affecting models 6210, 7210 and 8200v. Three lower-severity flaws were also fixed; no exploitation has been observed, and customers are urged to upgrade.
- CVE-2026-102255: pre-auth SSRF, CVSS 10.0, no known exploitation in the wild
- Affects SMA1000 6210, 7210 and 8200v on 12.4.3-03526 and 12.5.0-02952
- Fixed in 12.4.3-03670 and 12.5.0-03082, no workaround available
- Three other flaws rated 7.8, 7.2 and 5.5, up to remote code execution
Read next
Security