The affected versions include 12.4.3-03453 and 12.5.0-02835 of the firmware. These vulnerabilities pose a significant risk to administrators and users, allowing remote attacks that bypass authentication and potentially leading to full system control. (CVSS 10 — Critical): A pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
An attacker could exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.[/subscribe_to_unlock_form]
The affected versions include 12.4.3-03453 and 12.5.0-02835 of the firmware. These vulnerabilities pose a significant risk to administrators and users, allowing remote attacks that bypass authentication and potentially leading to full system control. (CVSS 10 — Critical): A pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
An attacker could exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.[emaillocker id="1283"]
(CVSS 7.8 — High): An attacker can impersonate an administrator and execute arbitrary OS commands, resulting in remote code execution. These vulnerabilities collectively present a severe risk to organizations that use SonicWall's Secure Mobile Access appliances.
We recommend you to update SonicWall Secure Mobile Access 1000 series appliances to given version link:https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW
The following reports contain further technical details:
[/emaillocker]