Full Report
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. [...]
Analysis Summary
# Vulnerability: SonicWall SMA1000 Server-Side Request Forgery (SSRF)
## CVE Details
- **CVE ID:** CVE-2026-102255
- **CVSS Score:** 10.0 (Critical)
- **CWE:** CWE-918 (Server-Side Request Forgery)
## Affected Systems
- **Products:** SonicWall SMA1000 Series (Enterprise Secure Remote Access Gateways)
- **Versions:**
- SMA 6210
- SMA 7210
- SMA 8200v
- **Configurations:** Systems with the "Appliance WorkPlace" interface enabled.
- *Note: SMA 100 Series and SSL-VPN on SonicWall firewalls are NOT affected.*
## Vulnerability Description
CVE-2026-102255 is a maximum-severity Server-Side Request Forgery (SSRF) vulnerability. The flaw resides in the **Appliance WorkPlace** interface. A remote, unauthenticated attacker can send specially crafted requests to the appliance, forcing it to issue requests on their behalf. This allows the attacker to bypass access controls, reach internal services (such as the local CouchDB instance), and perform unauthorized operations or administrative actions.
## Exploitation
- **Status:** Exploited in the wild. Honeypots have detected active exploitation attempts following the patch release.
- **Complexity:** Low
- **Attack Vector:** Network (Remote/Unauthenticated)
- **PoC Availability:** Technique details are public (Crafted `OPTIONS` requests targeting `127.0.0.1:5984`).
## Impact
- **Confidentiality:** High (Access to internal databases and credentials)
- **Integrity:** High (Ability to perform unauthorized operations/administrative tasks)
- **Availability:** High (Potential for system compromise or ransomware deployment)
## Remediation
### Patches
SonicWall released patches on Tuesday, October 6, 2026. Administrators should immediately update their SMA1000 firmware to the latest available version provided by the vendor.
### Workarounds
No specific official workarounds are listed to fully mitigate the flaw without patching. It is highly recommended to:
- Restrict access to the management/WorkPlace interface to trusted IP addresses only.
- Ensure the appliance is not exposed to the public internet unless absolutely necessary.
## Detection
- **Indicators of Compromise (IoC):**
- HTTP `OPTIONS` requests targeting the WorkPlace `Extraweb` interface.
- Logs showing requests to `127.0.0.1:5984` (internal CouchDB).
- Attempts to invoke the `_rewrite` function in CouchDB design documents.
- HTTP Basic Authorization headers containing default or common credentials (e.g., `admin:admin`).
- **Detection methods:** Monitor web server logs for unusual `OPTIONS` methods and path traversal attempts targeting internal ports.
## References
- SonicWall PSIRT Advisory: hxxps[://]psirt.global.sonicwall[.]com/vuln-detail/SNWLID-2026-0017
- NVD Detail: hxxps[://]nvd.nist[.]gov/vuln/detail/CVE-2026-102255
- Shadowserver SMA1000 Statistics: hxxps[://]dashboard.shadowserver[.]org/statistics/iot-devices/time-series/?date_range=7&vendor=sonicwall&model=sonicwall+sma+1000&dataset=count&limit=100&group_by=geo&stacking=stacked