SonicWall fixes critical flaw in business remote-access gateways
SonicWall has released security fixes for a critical weakness in certain SMA1000 remote-access appliances. These gateways let staff connect to business systems from outside the office. The advisory was issued on 6 October, with wider reporting on 7 October. SonicWall said it had no evidence that the vulnerabilities in this release were being exploited.
The main flaw, CVE-2026-102255, affects the Appliance WorkPlace interface. It is a server-side request forgery, or SSRF, vulnerability: an attacker tricks a trusted device into making requests on their behalf. Here, an unintended access route could let somebody without a login reach internal functions and perform unauthorised operations. This is different from merely guessing an employee’s password, so stronger passwords alone do not fix it.
The affected models are SMA1000 6210, 7210 and virtual 8200v appliances. The published affected builds include 12.4.3-03526 and earlier, and 12.5.0-02952 and earlier. SonicWall’s firewall SSL-VPN feature and the separate SMA 100 product family are outside this advisory’s scope.
For organisations using these gateways, the potential impact is unauthorised access to functions that help protect remote connections. The precise consequences depend on the installation; the advisory does not establish that any particular customer’s data was stolen.
Administrators should install the appropriate fixed hotfix: 12.4.3-03670 or later in that branch, or 12.5.0-03082 or later in its branch. Business owners can ask their IT supplier to confirm the model and full installed build number. A previous update does not necessarily include this new fix.







Comments