轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000007
[內容說明]
SonicWall針對SMA1000系列產品發布重大資安漏洞(CVE-2026-15409,CVSS:10.0),此為SSRF漏洞並存在於SMA1000系列產品設備工作介面中,未經身分驗證的遠端攻擊者可發出非預期請求。 備註:目前SonicWall PSIRT已調查多起案例,顯示該漏洞正被積極利用,建議儘速採取暫時緩解措施,以防止針對此漏洞可能的攻擊發生。
[影響平台]
SMA 1000系列產品 12.4.3-03245至12.4.3-03434(含)版本、 SMA 1000系列產品 12.5.0-02283至12.5.0-02800(含)版本
[建議措施]
請更新至以下版本: SMA 1000系列產品 12.4.3-03453(含)之後版本、 SMA 1000系列產品 12.5.0-02835(含)之後版本
Forward Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000007
[Description]
SonicWall has released a critical security vulnerability for SMA1000 series products (CVE-2026-15409, CVSS: 10.0). This is an SSRF vulnerability that exists in the device management interface of SMA1000 series products. An unauthenticated remote attacker can issue unexpected requests. Note: SonicWall PSIRT has currently investigated multiple cases, indicating that this vulnerability is being actively exploited. It is recommended to implement temporary mitigation measures as soon as possible to prevent potential attacks targeting this vulnerability.
[Affected Platforms]
SMA 1000 series products versions 12.4.3-03245 to 12.4.3-03434 (inclusive), SMA 1000 series products versions 12.5.0-02283 to 12.5.0-02800 (inclusive)
[Recommendations]
Please update to the following versions: SMA 1000 series products version 12.4.3-03453 (inclusive) and later, SMA 1000 series products version 12.5.0-02835 (inclusive) and later