decrypted · 11 october 2026 · vulnerabilities and patching · supply chain · surveillance and privacy

SonicWall's SMA1000 gets a second front door, and someone is already knocking

A remote access gateway is supposed to be the one door into a company that only the right people can open. This week SonicWall fixed a maximum severity flaw in its SMA1000 gateways that amounted to a second entrance nobody meant to build. Within days, a researcher reported probes that look like attempts to walk through it. If your organisation runs one of these appliances, this is a patch-and-check week, and the lesson underneath is about trust.

What was fixed

The flaw is CVE-2026-102255, covered by SonicWall advisory SNWLID-2026-0017. It is a server-side request forgery in the Appliance WorkPlace interface, which SonicWall attributes to an "unintended alternate access-path weakness". It affects the SMA1000 6210, 7210 and 8200v, and needs no login. The older SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected. SonicWall lists no workaround, only the hotfix. Published guidance quotes different build numbers, so take them from the advisory itself.

The receptionist problem

Imagine a receptionist who will phone any internal extension on a stranger's say-so, because calls from the front desk are always trusted. The stranger asks the desk to ring the finance office for them. That is server-side request forgery: the attacker cannot reach internal services, so they persuade the appliance, which can, to make the request on their behalf. SonicWall said an unauthenticated attacker could "direct the appliance to issue requests on their behalf".

What defenders are seeing

At release, SonicWall said there was no evidence of exploitation. Since then, Ryan Dewhurst of Previdian told BleepingComputer that his honeypots caught attempts consistent with this flaw. The requests used a crafted OPTIONS call against the WorkPlace Extraweb interface, aimed at a CouchDB database service listening inside the appliance, and tried the credentials admin:admin. Previdian has not established whether any attempt succeeded. This is one researcher's observation, not a confirmed campaign. Shadowserver tracks more than 400 SMA1000 appliances reachable from the internet.

A pattern, not an accident

In July, attackers used zero-days CVE-2026-15409 and CVE-2026-15410 for weeks, and CISA later linked some of those attacks to ransomware gangs. In September SonicWall warned that CVE-2026-83548 and CVE-2026-83549 were being chained. Dewhurst says this flaw sits in the same interface as earlier request-forgery bugs from July and September. BleepingComputer counts 19 SonicWall flaws added to CISA's exploited list over four years, 13 flagged as used by ransomware gangs.

The Secure by Design lesson

First, an internal service should never trust a request just because of where it came from. If the database behind the gateway demanded real credentials from everything, a forged request would be a nuisance rather than a way in. Second, the attacker's guess of admin:admin is a bet that vendors still ship default passwords. The Secure by Design position is that products should not.

The cost of applying this is modest for buyers: ask your vendor how internal services authenticate each other, ask for the history of flaws in the interface you expose, and decide whether a login page for staff needs to face the whole internet. Opinion, not advice, but a gateway that has needed three rounds of serious fixes since July has told you something about its design.

Also this week

Backup consoles in the firing line. Huntress reported exploitation of AhsayCBS, backup management software that BleepingComputer says managed service providers typically use, from 7 October, with at least five organisations targeted. Attackers chained CVE-2026-105133 and CVE-2026-105134 to run code without logging in, then planted webshells and a cryptominer disguised as a Microsoft Edge component. In one case they also loaded a vulnerable kernel driver, likely to give the miner more hardware access. Huntress corrected an earlier assessment to say versions up to and including 10.3.4 are affected, and no fixed version had been identified at the time of its report. Its advice is to restrict the management interface to trusted addresses or a VPN, and to rebuild any compromised host from a trusted backup, since attackers may have left further backdoors. A miner is the mild outcome: the same access could carry something worse. Ask your provider whether their backup console is on the internet.

Whose email is it when a supplier fails? More than 100 US lawmakers have written to Google and Spirit Airlines to halt a deal in which Google would pay $10 million for the bankrupt airline's internal data, reported by The Record to include about 100 million emails and 500 million Teams messages. Google says it is not seeking personal information and that an independent third party would deidentify the data first. The lawmakers reply that removing direct identifiers does not necessarily make a dataset anonymous. Spirit has shut down and could not be reached for comment, which is rather the point. It is a US case, but the question travels: if a supplier holding your staff's correspondence fails, who decides where it goes?

Sources

If you want a second pair of eyes on which of your suppliers' gateways face the internet, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.