SonicWall SMA1000: an unauthenticated SSRF, not a confirmed code execution
On 7 October 2026, CERT-FR published advisory CERTFR-2026-AVI-1275. The named builds are 12.5.0-03082 and 12.4.3-03670. CVE-2026-102255 is, on NVD, an unauthenticated SSRF, with no score in the record. The advisory says the vendor does not mention active exploitation. The CISA catalog does not list these four CVEs.

Original AI-generated illustration · SecuFocus
At a glance
Key points
If the appliance is not reachable from the internet, the action is less urgent. If it is, install the named build. Do not read “code execution” as an anonymous access already observed.
What changes
On 7 October 2026, CERT-FR published advisory CERTFR-2026-AVI-1275, citing the SonicWall bulletin of 6 October. The affected versions are SMA1000 12.5 before 12.5.0-03082, and versions before 12.4.3-03670. The advisory names four CVEs: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257 and CVE-2026-102258. It says the vendor does not mention active exploitation for now. It recalls that, this year, combinations of an authenticated code execution and an SSRF that bypasses authentication have already been exploited on this product. That reminder points at older alerts, not at a new line in the CISA catalog.
The CISA catalog, version 2026.10.04, 1,734 entries, reread on 7 October 2026, contains none of these four CVEs.
Scroll the table sideways to read every column.
| CVE | What NVD says | Score read |
|---|---|---|
| CVE-2026-102255 | Unauthenticated SSRF on the Work Place interface. A remote attacker can make the appliance issue requests. | not documented |
| CVE-2026-102256 | Post-authentication command injection, described for an administrator. The CVSS 3.1 vector starts with local access and low privileges. | 7.8 |
| CVE-2026-102257 | Zip Slip in the management console, high privileges, code execution. | 7.2 |
| CVE-2026-102258 | Stored XSS. The description says an authenticated administrator. The vector shows PR:N and user interaction. | 6.1 |
What we did not check
We do not have an SMA1000 appliance, and we did not replay the CVEs. The NVD records, published on 7 October 2026, are Awaiting Analysis. The CVE-2026-102255 record has no score in the page we read. For CVE-2026-102256 and CVE-2026-102258, the description and the vector do not say the same thing. This note does not reconcile them. “No active exploitation mentioned” is CERT-FR’s sentence about the vendor bulletin. It is not a SecuFocus test. The vendor page is not cited here.
The choice
If you do not have an SMA1000, there is nothing to install.
If the appliance is reachable from the internet, CERT-FR points to the vendor bulletin for builds 12.5.0-03082 and 12.4.3-03670. The new unauthenticated fact, on NVD, is an SSRF, not anonymous code execution. The other records require an account, or disagree between description and vector.
These four CVEs missing from the CISA catalog does not mean an exposed box can wait. It means they are not in version 2026.10.04.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- CERT-FR, advisory CERTFR-2026-AVI-1275, SonicWall SMA1000 ↗cert.ssi.gouv.fr ·
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.