轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202609-00000001
[內容說明]
SonicWall針對SMA1000系列產品發布重大資安漏洞(CVE-2026-83548,CVSS:10.0),此為SSRF漏洞並存在於SMA1000系列產品設備工作介面中,未經身分驗證的遠端攻擊者可能利用此漏洞非法存取敏感功能並執行未經授權的操作。
備註:目前SonicWall PSIRT已調查一起案例,顯示該漏洞正被利用,建議儘速採取暫時緩解措施,以防止針對此漏洞可能的攻擊發生。
[影響平台]
● SMA1000 Models - 6210, 7210, 8200v 產品 12.43-03453(含)以前版本
● SMA1000 Models - 6210, 7210, 8200v 產品 12.5.0-02835(含)以前版本
[建議措施]
請更新至以下版本:
SMA1000 Models - 6210, 7210, 8200v 產品 12.4.3-03526(含)之後版本、
SMA1000 Models - 6210, 7210, 8200v 產品 12.5.0-02952(含)之後版本
[參考資料]
1. https://www.twcert.org.tw/tw/cp-169-11174-8625e-1.html
Forwarded from Taiwan Computer Emergency Response Coordination Center Cybersecurity Information Alert TWCERTCC-200-202609-00000001
[Content Description]
SonicWall has released a major security vulnerability advisory for its SMA1000 series products (CVE-2026-83548,CVSS:10.0). This is an SSRF vulnerability present in the SMA1000 series product device work interface. Unauthenticated remote attackers may exploit this vulnerability to illegally access sensitive functions and perform unauthorized operations.
Note: SonicWall PSIRT has currently investigated a case indicating that this vulnerability is being exploited. It is recommended to take temporary mitigation measures as soon as possible to prevent potential attacks targeting this vulnerability.
[Affected Platforms]
● SMA1000 Models - 6210, 7210, 8200v products version 12.43-03453(inclusive) and earlier
● SMA1000 Models - 6210, 7210, 8200v products version 12.5.0-02835(inclusive) and earlier
[Recommended Measures]
Please update to the following versions:
SMA1000 Models - 6210, 7210, 8200v products version 12.4.3-03526(inclusive) or later,
SMA1000 Models - 6210, 7210, 8200v products version 12.5.0-02952(inclusive) or later
[References]
1. https://www.twcert.org.tw/tw/cp-169-11174-8625e-1.html