CVE-2026-102256 PUBLISHED

Assigner: sonicwall
Reserved: 28.09.2026 Published: 07.10.2026 Updated: 07.10.2026

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Product Status

Vendor SonicWall
Product SMA1000
Versions Default: unknown
  • Version 12.4.3-03526 (platform-hotfix) and older versions is affected
  • Version 12.5.0-02952 (platform-hotfix) and older versions is affected

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE