【資安漏洞預警】SonicWall 旗下SMA100系列產品存在重大資安漏洞(CVE-2025-40599)
[Security Vulnerability Warning] SonicWall's SMA100 series products have a major security vulnerability (CVE-2025-40599)

發布單位:計算機與資訊網路中心
日期範圍:2025/7/25 ~ 2026/1/25
 
發布單位:計算機與資訊網路中心
日期範圍:2025/7/25 ~ 2026/1/25
行政 行政公告
全體

轉發 台灣電腦網路危機處理暨協調中心 TWCERTCC-200-202507-00000022

[內容說明]
SonicWall針對SMA100系列產品發布重大資安漏洞(CVE-2025-40599,CVSS:9.1),SMA100系列產品的Web管理介面存在經過驗證的任意檔案上傳漏洞,遠端攻擊者若具有管理員權限,便可藉此上傳任意檔案至系統,可能導致遠端程式碼執行。

[影響平台]
SMA 100系列產品 10.2.1.15-81sv(含)之前版本

[建議措施]
更新SMA 100系列產品至 10.2.2.1-90sv (含)之後版本

[參考資料]
https://www.twcert.org.tw/tw/cp-169-10282-defea-1.html

Forwarded by Taiwan Computer Network Crisis Management and Coordination Center TWCERTCC-200-202507-00000022

[Content Description]
SonicWall released a major security vulnerability (CVE-2025-40599, CVSS: 9.1) for the SMA100 series products. The web management interface of the SMA100 series products has a verified arbitrary file upload vulnerability. If a remote attacker has administrator privileges, he can upload any file to the system, which may lead to remote code execution.

[Affected Platform]
SMA 100 series products 10.2.1.15-81sv (inclusive) and earlier versions

[Recommended measures]
Update SMA 100 series products to 10.2.2.1-90sv (inclusive) and later versions

[References]
https://www.twcert.org.tw/tw/cp-169-10282-defea-1.html


相關附件
system_update_alt參考資料
Top↑