SonicWall warns of max severity SSRF flaw in SMA1000 gateways

A Critical Flaw in SonicWall Gateways Exposes Enterprise Networks to Remote Attacks

A severe security vulnerability has been discovered in SonicWall’s SMA1000 series appliances, potentially putting thousands of enterprise networks at risk. The flaw, which allows remote attackers to exploit server-side request forgery (SSRF) weaknesses, has been patched by SonicWall with a hotfix release.

The issue affects SMA1000 6210, 7210, and 8200v models, but not the SMA 100 Series or SSL-VPN running on SonicWall firewalls. The vulnerability stems from an unintended alternate access-path weakness that can be exploited in low-complexity attacks by remote attackers without privileges.

According to SonicWall, an attacker could abuse this path to direct the appliance to issue requests on their behalf and reach internal functionality, performing unauthorized operations in the process. While there is no evidence that these vulnerabilities are being actively exploited, SonicWall strongly advises customers to deploy the hotfixes released on Tuesday to block potential attacks targeting their virtual or physical appliances.

The affected SMA1000 series appliances are commonly used by government agencies, Managed Service Providers (MSSPs), and large corporations to provide secure remote access to internal apps and corporate networks. This vulnerability is particularly concerning given recent reports of threat actors exploiting several other SMA1000 security vulnerabilities in zero-day attacks.

In fact, since the start of the year, SonicWall has warned customers about multiple SMA1000 security flaws being exploited by attackers. In July, two SMA1000 zero-days were exploited to install custom malware on vulnerable VPN appliances, which was linked to ransomware gangs by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Last month, SonicWall also warned customers that attackers were chaining two new zero-days to execute remote code on vulnerable SMA1000 gateways.

Given the high-profile nature of these attacks and the severity of this latest vulnerability, it’s essential for all affected organizations to take immediate action. If you’re using an SMA1000 series appliance, make sure to deploy the hotfixes released by SonicWall as soon as possible to minimize your risk exposure. Additionally, consider conducting a thorough security audit to identify any other potential vulnerabilities in your network.

Don’t wait until it’s too late – secure your enterprise network today and prevent potentially catastrophic consequences.


Source: Bleeping Computer — 2026-10-07