SonicWall SMA1000 CVSS 10 flaw now seeing exploitation attempts
EditorialBy TrustList Editorial
Previdian's sensor logged 135 attempts from two US addresses, 24 on 9 October and 111 on 10 October. SonicWall's advisory SNWLID-2026-0017 said it had found no sign of exploitation.
About SonicWall SMA1000 CVSS 10 flaw now seeing exploitation attempts
SonicWall SMA1000 CVSS 10 flaw now seeing exploitation attempts
10 October 2026: Attackers are now probing SonicWall SMA1000 appliances for CVE-2026-102255, a pre-authentication server-side request forgery in the Appliance Work Place interface with a CVSS score of 10.0. Security firm Previdian has logged 135 attempts and rates the flaw as under active exploitation, so any appliance still on an unpatched build should be treated as a target.
Not yet independently verified. SonicWall's advisory page could not be read; the fixed versions and the CouchDB detail come from researchers quoted by SC World, and the affected builds from Previdian. The attempts are not confirmed compromises, and the CISA catalogue status is taken from Previdian and SC World rather than checked on CISA's own list. We will update this when it can be confirmed, and remove this note.
What Previdian's sensor recorded
Previdian's page shows no attempts from 4 to 8 October, 24 on 9 October and 111 on 10 October, all from two IP addresses in the United States and all seen by a single sensor. It reports attempts only, with no confirmed compromise, and says the flaw is not in the CISA Known Exploited Vulnerabilities catalogue. It rates the likelihood of exploitation as 0.5% on the EPSS scale.
The free page does not show the attacker addresses, the request paths or the payloads, and those details are held back for paying customers. Previdian's timeline puts the CVE publication on 7 October, its first recorded indicators early on 9 October and a virtual patch for web application firewalls later that day.
SonicWall's advisory SNWLID-2026-0017 said the company had found no evidence of exploitation, as Security Affairs reported on 7 October. We covered the flaw in our 7 October item.
The third CVSS 10 request-forgery flaw in nine months
Denis Calderone, chief technology officer at Suzu Labs, told SC World this is the third CVSS 10.0 pre-authentication request forgery in the Work Place interface in nine months, after July and September. Each lets an unauthenticated attacker make the appliance proxy requests to internal services that were never meant to be reachable from outside.
He says the attempts are aimed at the CouchDB service on localhost, and that a public Metasploit module written for the September chain already shows how CouchDB access leads to root-level code execution on these appliances. Previdian classes the weakness as CWE-918 and CWE-441, an unintended proxy.
Calderone's sharpest point concerns patching history: the firmware released in September to fix the last chain is, he says, exactly what this flaw affects, so every appliance patched after September is exposed again.
Affected models and fixed builds
Affected models are the SMA1000 6210, 7210 and 8200v running these builds or older:
- 12.4.3-03526 (platform-hotfix)
- 12.5.0-02952 (platform-hotfix)
The SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected. Security Affairs says SonicWall offers no workaround and distributes the hotfix through the MySonicWall portal. Calderone gives the fixed versions as 12.4.3-03670 and 12.5.0-03082.
The appliance reboots during installation and drops every VPN session, so he advises a short maintenance window, an exported configuration and console access in hand beforehand, and not applying the hotfix over the VPN itself.
What to look for after patching
SonicWall has published no indicators of compromise for this flaw, unlike the July advisory. Calderone says the internal architecture is unchanged, so the July patterns still apply:
- unexpected routes in /var/lib/unit/conf.json
- HTTP 200 responses to /api/login or /api/logout in extraweb_access.log
- path traversal entries in ctrl-service.log
- authentication attempts from the appliance's own address against the company's domain controllers
If anything looks wrong he recommends re-imaging before installing the new firmware: "Patching a compromised box just gives you a patched compromised box."
Why not wait for a CISA listing
Shane Barney, chief information security officer at Keeper Security, says SSRF flaws in edge appliances bypass the perimeter entirely, and that "security teams cannot afford to take a 'wait and see' approach" over the catalogue entry. He advises isolating the Work Place interface from the public internet if patching must wait, and reviewing logs for unusual outbound or internal requests.
Jason Soroko, senior fellow at Sectigo, notes that multifactor authentication does not close this route, because the appliance that controls remote access is itself the entry point. On the unconfirmed attempts he says: "That distinction matters for reporting, but security teams already have enough evidence to act."
Our VPN software category lists 13 products and our network security software category lists six.
Company profile on TrustList: SonicWall
Related on TrustList:
- ChromeOS 16805.33.0 fixes 106 Chrome bugs, five of them Critical
- SonicWall patches CVSS 10 pre-login flaw in SMA1000 gateways
Sources
Categories & features
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.