CVE-2026-102257

SMA: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-102257)

Description

A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.

Source: BSI

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

SonicWallSMA
1000 Models 6210 <12.4.3-036701000 Models 6210 <12.5.0-030821000 Models 7210 <12.4.3-036701000 Models 7210 <12.5.0-030821000 Models 8200v <12.4.3-036701000 Models 8200v <12.5.0-03082

Metrics

7.2
Source: cna-v3
49.7 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
high
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-08 11:27 UTC
CWE-22

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-08 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-102257","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
    • SSVC: {"id":"CVE-2026-102257","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  2. CVE Modified2026-10-07 15:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    • SSVC: {"id":"CVE-2026-102257","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  3. New CVE Received2026-10-07 14:17 UTC· PSIRT@sonicwall.com
    • Description: A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.
    • CWE: CWE-22
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/102xxx/CVE-2026-102257.json">CVE-2026-102257</a>
    • Reference: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017

Linked CVEs

Linked advisories