Critical · published September 2, 2026
CVSS calls it critical at 10.0. It is confirmed in active exploitation. It sits in the 51.2th percentile for exploit probability.
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
| Product | Versions | Fixed in |
|---|---|---|
| sonicwall/sma8200v | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall/sma8200v | ≥ 12.5.0, < 12.5.0-02952 | 12.5.0-02952 |
| sonicwall/sma6210_firmware | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall/sma6210_firmware | ≥ 12.5.0, < 12.5.0-02952 | 12.5.0-02952 |
| sonicwall/sma7210_firmware | < 12.4.3-03526 | 12.4.3-03526 |
| sonicwall/sma7210_firmware | ≥ 12.5.0, < 12.5.0-02952 | 12.5.0-02952 |