:::

【資安漏洞預警】SonicWall 旗下SMA1000系列產品存在重大資安漏洞 (CVE-2026-15409)
【Security Vulnerability Alert】A critical security vulnerability exists in SonicWall SMA1000 series products (CVE-2026-15409)

公告類別:行政公告
發佈日期:2026/07/21 至 2027/01/21
點閱數:121

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000007

[內容說明]
SonicWall針對SMA1000系列產品發布重大資安漏洞(CVE-2026-15409,CVSS:10.0),此為SSRF漏洞並存在於SMA1000系列產品設備工作介面中,未經身分驗證的遠端攻擊者可發出非預期請求。 備註:目前SonicWall PSIRT已調查多起案例,顯示該漏洞正被積極利用,建議儘速採取暫時緩解措施,以防止針對此漏洞可能的攻擊發生。

[影響平台]
SMA 1000系列產品 12.4.3-03245至12.4.3-03434(含)版本、 SMA 1000系列產品 12.5.0-02283至12.5.0-02800(含)版本

[建議措施]
請更新至以下版本: SMA 1000系列產品 12.4.3-03453(含)之後版本、 SMA 1000系列產品 12.5.0-02835(含)之後版本
Forward Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000007

[Description]
SonicWall has released a critical security vulnerability for SMA1000 series products (CVE-2026-15409, CVSS: 10.0). This is an SSRF vulnerability that exists in the device management interface of SMA1000 series products. An unauthenticated remote attacker can issue unexpected requests. Note: SonicWall PSIRT has currently investigated multiple cases, indicating that this vulnerability is being actively exploited. It is recommended to implement temporary mitigation measures as soon as possible to prevent potential attacks targeting this vulnerability.

[Affected Platforms]
SMA 1000 series products versions 12.4.3-03245 to 12.4.3-03434 (inclusive), SMA 1000 series products versions 12.5.0-02283 to 12.5.0-02800 (inclusive)

[Recommendations]
Please update to the following versions: SMA 1000 series products version 12.4.3-03453 (inclusive) and later, SMA 1000 series products version 12.5.0-02835 (inclusive) and later

返回列表