SonicWall SMA 零日漏洞遭积极利用,企业基础设施面临未经授权的 Root 权限风险

SonicWall SMA zero-day CVE-2026-15409 CVE-2026-15410 enterprise network security unauthenticated root access
V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 
2026年7月23日
4 分钟阅读
SonicWall SMA 零日漏洞遭积极利用,企业基础设施面临未经授权的 Root 权限风险

TL;DR

• SonicWall SMA 1000 系列设备正面临勒索软件组织的积极利用。 • 攻击者通过串联两个关键漏洞获取了未经授权的 Root 控制权。 • CVE-2026-15409 (SSRF) 和 CVE-2026-15410 (权限提升) 正在被利用。 • 'ROOTRUN' 和 'KNUCKLEBALL' 等恶意工具确保了持久的后门访问。 • 管理员必须立即检查日志并安装紧急安全更新。

SonicWall SMA 零日漏洞遭积极利用,企业基础设施面临未经授权的 Root 权限风险

如果您正在使用 SonicWall SMA 1000 系列设备,请立即停止手头工作并检查日志。网络安全机构和研究人员已证实,两个严重的零日漏洞——CVE-2026-15409 和 CVE-2026-15410——正遭到野外积极利用。这并非理论上的风险;攻击者正利用这些漏洞绕过身份验证、提升权限,并获取企业网络的完全 Root 级控制权。

线索直指一些重量级攻击者,包括 Inc 勒索软件组织和一个被称为 UTA0533 的神秘黑客团体。自 2026 年 6 月 22 日首次出现异常迹象以来,这些组织一直在部署定制恶意软件、窃取凭据,并在企业环境中横向移动,如入无人之境。

攻击剖析

整场攻击始于 CVE-2026-15409,这是一个服务器端请求伪造 (SSRF) 漏洞,其 CVSS 评分为满分 10.0。这堪称“大门敞开”的典型案例。通过利用基于 WebSocket 的隧道技术,未经身份验证的攻击者可以直接与设备本地主机上的服务进行通信。本质上,他们绕过了旨在防止内部管理接口暴露在公共互联网上的安全检查。

一旦在边界打开缺口,他们便转向 CVE-2026-15410。这是一个隐藏在 remove_hotfix 工作流程中的高危权限提升漏洞。这是一种路径遍历技巧,允许攻击者在几步之内从“互联网上的陌生人”变身为“Root 级管理员”。将这两个漏洞串联起来,就等于将整个基础设施的钥匙拱手让人。

SonicWall SMA 零日漏洞遭积极利用,企业基础设施面临未经授权的 Root 权限风险

图片来源:The Hacker News

谁在幕后操纵?目的何在?

Rapid7 MDR 团队一直在进行深入调查,记录了这些攻击者不仅是入侵,更是在“安营扎寨”。他们发现了多种恶意载荷,包括 'ROOTRUN'(一种 setuid 二进制文件,确保即使设备重启也能保持 Root 权限)和 'KNUCKLEBALL'(一种旨在将恶意 Java 归档文件 (JAR) 注入系统的 Python 脚本)。

攻击工具包远不止于此。研究人员还发现了:

  • Suo5: 一种 HTTP 代理工具,用于保持通信的隐蔽性。
  • ORANGETAIL: 一个 Web Shell,为远程命令执行和文件窃取提供了便捷界面。
  • 凭据窃取器: 这些工具尤为危险,专门针对会话数据库和多因素身份验证 (MFA) 种子。

当 Inc 勒索软件组织获取 MFA 种子时,您的二次身份验证实际上已失效。他们利用这种访问权限来绘制网络拓扑、窃取敏感数据,并为最后一步——大规模加密——做准备。

漏洞概览

CVE 标识符 类型 严重程度 影响
CVE-2026-15409 SSRF 严重 (10.0) 未经授权的本地主机隧道访问
CVE-2026-15410 权限提升 高 (7.2) Root 级代码执行

如何加固您的网络

CISA 已于 2026 年 7 月 14 日将这两个漏洞列入其“已知被利用漏洞”(KEV) 目录。如果您尚未修补,那么您的安全防护已经严重滞后。

SonicWall 已经发布了热修复补丁,您需要立即安装。请前往 SonicWall 官方 PSIRT 公告获取适用于您的 SMA 1000 系列设备(特别是 6210、7210 和 8200v 型号)的补丁。

您的紧急待办事项:

  1. 盘点: 确认网络中究竟有哪些 SMA 1000 设备。
  2. 修补: 立即应用制造商提供的热修复补丁。
  3. 审计: 仔细检查系统日志。寻找任何可疑迹象——WebSocket 隧道尝试或 'ROOTRUN' 等二进制文件的存在都是重大危险信号。
  4. 重置: 如果怀疑已被入侵,请假设一切已遭破坏。轮换设备上的所有凭据,包括管理员密码和那些关键的 MFA 种子。

Volexity 记录的代理方法清楚地提醒我们,边缘设备是现代网络中最危险的故障点。将 SSRF 与路径遍历串联起来是一种外科手术式的精准打击,这是我们越来越频繁看到的战术。

随着研究人员追踪新的载荷和 Inc 组织不断演变的战术,局势仍在变化。不要等到收到勒索信才开始加固边界。请务必更新设备、监控流量,并假设如果您已暴露,那么已经有人在寻找入侵途径了。

V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 

Viktor Sokolov is a network engineer and protocol security researcher with deep expertise in how data travels across the internet and where it becomes vulnerable. He spent eight years working for a major internet service provider, gaining firsthand knowledge of traffic analysis, deep packet inspection, and ISP-level surveillance capabilities. Viktor holds multiple Cisco certifications (CCNP, CCIE) and a Master's degree in Telecommunications Engineering. His insider knowledge of ISP practices informs his passionate advocacy for VPN use and encrypted communications.

相关新闻

Qilin Ransomware Group Targets Enterprise VPN Infrastructure in Coordinated Attacks Against Major Network Vendors
Qilin ransomware

Qilin Ransomware Group Targets Enterprise VPN Infrastructure in Coordinated Attacks Against Major Network Vendors

Qilin ransomware is exploiting critical vulnerabilities in major VPN vendors. Learn how this RaaS group breaches networks and how to protect your infrastructure.

作者: Elena Voss 2026年7月28日 4 分钟阅读
common.read_full_article
State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy
MarkiRAT malware

State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

State-sponsored hackers are using fake VPN apps to deploy the MarkiRAT malware, targeting Persian speakers globally to steal sensitive data and monitor devices.

作者: James Okoro 2026年7月27日 4 分钟阅读
common.read_full_article
State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy
state-sponsored spyware

State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

Hackers are using trojanized VPN apps to steal private messages and monitor devices. Learn how Bahamut and TAG-182 spyware bypass security to compromise your data.

作者: Viktor Sokolov 2026年7月26日 5 分钟阅读
common.read_full_article
Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns
SonicWall SMA1000

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns

SonicWall SMA1000 appliances are under attack by UTA0533 using zero-day exploits. Patch immediately to prevent root-level access and data theft.

作者: Elena Voss 2026年7月25日 4 分钟阅读
common.read_full_article