【Security Vulnerability Alert】A critical security vulnerability exists in SonicWall SMA1000 series products (CVE-2026-15409)

 
2026/7/21 ~ 2027/1/21
View Count:36

Forward Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000007

[Description]
SonicWall has released a critical security vulnerability for SMA1000 series products (CVE-2026-15409, CVSS: 10.0). This is an SSRF vulnerability that exists in the device management interface of SMA1000 series products. An unauthenticated remote attacker can issue unexpected requests. Note: SonicWall PSIRT has currently investigated multiple cases, indicating that this vulnerability is being actively exploited. It is recommended to implement temporary mitigation measures as soon as possible to prevent potential attacks targeting this vulnerability.

[Affected Platforms]
SMA 1000 series products versions 12.4.3-03245 to 12.4.3-03434 (inclusive), SMA 1000 series products versions 12.5.0-02283 to 12.5.0-02800 (inclusive)

[Recommendations]
Please update to the following versions: SMA 1000 series products version 12.4.3-03453 (inclusive) and later, SMA 1000 series products version 12.5.0-02835 (inclusive) and later

Files
None
Top↑