【資安漏洞預警】SonicWall 旗下SMA1000系列產品存在重大資安漏洞 (CVE-2026-15409)
【Security Vulnerability Alert】A critical security vulnerability exists in SonicWall SMA1000 series products (CVE-2026-15409)

發布單位:圖資處數位服務組
日期範圍:2026/7/21 ~ 2027/1/21
 
發布單位:圖資處數位服務組
日期範圍:2026/7/21 ~ 2027/1/21
行政 行政公告
全體

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000007

[內容說明]
SonicWall針對SMA1000系列產品發布重大資安漏洞(CVE-2026-15409,CVSS:10.0),此為SSRF漏洞並存在於SMA1000系列產品設備工作介面中,未經身分驗證的遠端攻擊者可發出非預期請求。 備註:目前SonicWall PSIRT已調查多起案例,顯示該漏洞正被積極利用,建議儘速採取暫時緩解措施,以防止針對此漏洞可能的攻擊發生。

[影響平台]
SMA 1000系列產品 12.4.3-03245至12.4.3-03434(含)版本、 SMA 1000系列產品 12.5.0-02283至12.5.0-02800(含)版本

[建議措施]
請更新至以下版本: SMA 1000系列產品 12.4.3-03453(含)之後版本、 SMA 1000系列產品 12.5.0-02835(含)之後版本

Forward Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000007

[Description]
SonicWall has released a critical security vulnerability for SMA1000 series products (CVE-2026-15409, CVSS: 10.0). This is an SSRF vulnerability that exists in the device management interface of SMA1000 series products. An unauthenticated remote attacker can issue unexpected requests. Note: SonicWall PSIRT has currently investigated multiple cases, indicating that this vulnerability is being actively exploited. It is recommended to implement temporary mitigation measures as soon as possible to prevent potential attacks targeting this vulnerability.

[Affected Platforms]
SMA 1000 series products versions 12.4.3-03245 to 12.4.3-03434 (inclusive), SMA 1000 series products versions 12.5.0-02283 to 12.5.0-02800 (inclusive)

[Recommendations]
Please update to the following versions: SMA 1000 series products version 12.4.3-03453 (inclusive) and later, SMA 1000 series products version 12.5.0-02835 (inclusive) and later


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
Top↑