VDB

CVE-2026-102257

CVE-2026-102257 PUBLISHED CVSS 8.600000381469727 HIGH

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 10.0, CVEs: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, Summary: 1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations. CVSS Score: 10.0 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-918: Server-Side Request Forgery (SSRF) CWE-441: Unintended Proxy or Intermediary ('Confused Deputy') 2) CVE-2026-102256 - Post-authentication Remote Code Execution (RCE) Vulnerability Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. CVSS Score: 7.8 CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3) CVE-2026-102257 - Post-authentication Zip Slip Vulnerability A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution. CVSS Score: 7.2 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Risk Scores

CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N

Timeline

  • Oct 7, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›