CVE-2026-102257 PUBLISHED

Assigner: sonicwall
Reserved: 28.09.2026 Published: 07.10.2026 Updated: 07.10.2026

A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.

Product Status

Vendor SonicWall
Product SMA1000
Versions Default: unknown
  • Version 12.4.3-03526 (platform-hotfix) and older versions is affected
  • Version 12.5.0-02952 (platform-hotfix) and older versions is affected

Credits

  • Brian Mariani finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE