The Dutch NCSC said SonicWall fixed four critical flaws in SMA1000, including pre-authentication server-side request forgery (SSRF) and post-authentication OS command-injection remote code execution, each rated CVSS 10.0 under CVE-2026-102258, CVE-2026-102257, CVE-2026-102255, and CVE-2026-102256. The appliance sits at the edge, so the issue lands on a trust boundary many teams use to keep internal services off the internet.
The SSRF bug lets an unauthenticated outsider make the appliance send internal requests on their behalf, which means the gateway can become the path into back-end services instead of the barrier in front of them. The command-injection flaw then extends that risk to the management plane: once authenticated, an attacker can run operating-system commands on the appliance itself.
For organizations that use SMA1000 as an internet-facing remote-access gateway, the lasting exposure is not just the box but whatever internal endpoints it can reach and vouch for. The advisory does not report active exploitation, but it does show that both perimeter trust and local administration are in scope here.
SonicWall ha rilasciato aggiornamenti di sicurezza per sanare 4 vulnerabilità, di cui 1 con gravità "critica" e 2 con gravità "alta", che interessano i modelli 6210, 7210 e 8200v appartenenti alla serie SMA1000.