SonicWall SMA 1000 Series <= 12.4.3-03526 / 12.5.x <= 12.5.0-02952 Multiple Vulnerabilities (SNWLID-2026-0017)

critical Nessus Plugin ID 364476

Synopsis

The remote device is affected by multiple vulnerabilities.

Description

The remote host is a SonicWall SMA 1000 Series device that is affected by multiple vulnerabilities:

- A pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote, unauthenticated attacker could potentially direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations. (CVE-2026-102255)

- A Zip Slip vulnerability in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution. (CVE-2026-102257)

- A post-authentication improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the SMA1000 appliance which, in specific conditions, could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. (CVE-2026-102256)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to SonicWall SMA 1000 Series version 12.4.3-03670 or 12.5.0-03082 or later.

See Also

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017

Plugin Details

Severity: Critical

ID: 364476

File Name: sonicwall_sma_SNWLID-2026-0017.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 10/9/2026

Updated: 10/9/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 8

Percentile: 99.69

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-102255

CVSS v3

Risk Factor: Critical

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: x-cpe:/o:sonicwall:firmware

Required KB Items: Settings/ParanoidReport, installed_sw/SonicWall Secure Mobile Access

Patch Publication Date: 10/6/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258

IAVA: 2026-A-1104