Executive brief
A security vulnerability has been found in the SonicWall SMA1000 series, a remote access gateway used by employees to securely connect to corporate resources. An unauthorized attacker can trick the appliance into making network requests to internal or external locations it shouldn't access. This could allow an attacker to probe internal network services that are otherwise protected or bypass security controls.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the Work Place interface of SonicWall SMA1000 appliances. The flaw allows a remote, unauthenticated attacker to send crafted requests that force the appliance to initiate outbound network connections to arbitrary destinations. This can be leveraged to scan internal network segments, interact with internal services behind the firewall, or potentially exfiltrate sensitive metadata. The vulnerability affects specific firmware versions in the 12.4.3 and 12.5.0 branches. Users are advised to consult SonicWall's PSIRT for specific patch availability.
Affected products
- SonicWall SMA1000 12.4.3-03245 to 12.4.3-03434, 12.5.0-02283 to 12.5.0-02800
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory