CVE-2026-102256
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
| CWE | CWE-78 |
| Vendor | sonicwall |
| Product | sma1000 |
| Published | Oct 7, 2026 |
| Last Updated | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonicwall sma1000
Be the first to know when new high vulnerabilities affecting sonicwall sma1000 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SonicWall / SMA1000
12.4.3-03526 (platform-hotfix) and older versions 12.5.0-02952 (platform-hotfix) and older versions