{"id":"CVE-2026-102257","title":"A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execut…","summary":"A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execut…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"SonicWall","product":"SMA1000","affected":["SMA1000 12.4.3-03526 (platform-hotfix) and older versions","SMA1000 12.5.0-02952 (platform-hotfix) and older versions"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T15:16:56.143","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102257","references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017","label":"PSIRT@sonicwall.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-07T14:53:20.771218Z"},"ingestedAt":"2026-10-07T14:33:21.950Z","slug":"CVE-2026-102257","body":"## Overview\n\nA Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217554,"id":"CVE-2026-102257","ts":1791387467656,"field":"cvss","old":null,"new":"7.2"},{"seq":217553,"id":"CVE-2026-102257","ts":1791387467656,"field":"severity","old":"none","new":"high"}]}