peter bassill · operator
$ cve CVE-2026-102255 JSON

CVE-2026-102255

10.0
CRITICAL · CVSS 3.1 · EPSS 0.5% (pctl 39)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS0.48% — more likely to be exploited than 39% of all CVEs
WeaknessCWE-441
On CISA KEVno
Public exploitnone known
Published2026-10-07
Last modified2026-10-07

References

→ the Explorer  ·  watch your stack  ·  NVD