Skip to content

SonicWall SMA1000 pre-auth SSRF CVE-2026-102255 scores 10.0

SonicWall patched CVE-2026-102255, a CVSS 10.0 pre-auth SSRF in SMA1000 WorkPlace. SonicWall reports no confirmed exploitation; Previdian says its honeypots logged matching probes.

Published 2 min read

SonicWall has patched CVE-2026-102255, a pre-authentication server-side request forgery (SSRF) flaw in the SMA1000 WorkPlace interface, scored 10.0. The fix shipped on October 6 in advisory SNWLID-2026-0017. Whether anyone is exploiting it is where the sources diverge.

What's affected

The bug is in WorkPlace, the portal SMA1000 users authenticate against, and it is reachable before authentication. Affected appliances are the SMA 6210, 7210 and 8200v. SonicWall says the SMA 100 Series and the SSL-VPN on SonicWall firewalls are not affected.

SonicWall released hotfixes the same day. Reported fixed builds differ between redistributing advisories, so pull the exact hotfix version from SonicWall's PSIRT entry for SNWLID-2026-0017 rather than any secondary summary. Singapore's CSA advisory lists platform hotfix 12.4.3-03453 or 12.5.0-02835 or later.

Exploitation status

SonicWall's advisory states there is no evidence that any vulnerability in this release is being exploited in the wild, and as of October 8 CVE-2026-102255 was not in CISA's KEV catalog.

Against that, BleepingComputer reports that Ryan Dewhurst, founder of Previdian, saw probing on his honeypot network consistent with the flaw. Dewhurst was explicit about the limit of that signal: Previdian has not established "whether those attempts would have successfully compromised any systems." So the honest read is probing, not confirmed compromise — attempts that match the vulnerable path, not proof it worked.

The characteristics Dewhurst described, reported by BleepingComputer and reproduced here as observed behaviour (not vendor IOCs):

- OPTIONS request to the WorkPlace Extraweb interface
- Attempt to reach the internal CouchDB service at 127.0.0.1:5984
- Attempt to invoke the _rewrite function of a CouchDB design document
- HTTP Basic Authorization header using credentials admin:admin

Action checklist

  1. Apply the SNWLID-2026-0017 hotfix to every SMA 6210/7210/8200v appliance. A CVSS 10.0 pre-auth bug on an internet-facing VPN gateway is not something to schedule for the next maintenance window.
  2. Until patched, restrict WorkPlace exposure where you can, and watch for the request pattern above against the Extraweb interface.
  3. Review access logs for anomalous OPTIONS requests and internal-service callbacks during the exposure window.

Context

SMA1000 has been a target before. Earlier this year CVE-2026-15409 and CVE-2026-15410 were exploited for weeks to plant custom malware on the appliances, and CISA tied that activity to ransomware crews. A pre-auth 10.0 on the same product line, patched quietly in a batch advisory, is exactly the kind of flaw that gets a public PoC and then a KEV listing. The vendor says it isn't exploited yet; the probing says attackers are already looking.

Related stories