CVE-2026-102257
SMA: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-102257)
Description
A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.
Source: BSI
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1000 Models 6210 <12.4.3-036701000 Models 6210 <12.5.0-030821000 Models 7210 <12.4.3-036701000 Models 7210 <12.5.0-030821000 Models 8200v <12.4.3-036701000 Models 8200v <12.5.0-03082Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-08 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-102257","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
- SSVC: {"id":"CVE-2026-102257","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
- CVE Modified2026-10-07 15:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- SSVC: {"id":"CVE-2026-102257","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
- New CVE Received2026-10-07 14:17 UTC· PSIRT@sonicwall.com
- Description: A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.
- CWE: CWE-22
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/102xxx/CVE-2026-102257.json">CVE-2026-102257</a>
- Reference: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
Linked CVEs
- CVE-2026-102258
Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC)…
mediumCVSSv3 6.1 - CVE-2026-102257
A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside t…
highCVSSv3 7.2 - CVE-2026-102256
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been ide…
highCVSSv3 7.8 - CVE-2026-102255
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
criticalCVSSv3 10.0