SonicWall SMA 1000 系列設備發現 CVSS 10.0 嚴重零日漏洞

SonicWall SMA 1000 CVE-2026-15409 zero-day vulnerability enterprise network security SSRF exploit
V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 
2026年7月29日
4 分鐘閱讀
SonicWall SMA 1000 系列設備發現 CVSS 10.0 嚴重零日漏洞

TL;DR

• SonicWall SMA 1000 系列發現嚴重的 CVSS 10.0 漏洞鏈。 • 攻擊者正積極利用 CVE-2026-15409 與 CVE-2026-15410 進行勒索軟體攻擊。 • 該漏洞允許未經身份驗證的攻擊者取得完整的根權限控制。 • Rapid7 已證實 INC 勒索軟體組織正針對這些漏洞進行攻擊。 • 必須立即更新韌體以保護企業環境。

SonicWall SMA 1000 系列設備發現 CVSS 10.0 嚴重零日漏洞

如果您正在使用 SonicWall SMA 1000 系列設備,請立即停下手邊工作並檢查韌體版本。安全研究人員與 SonicWall 已證實,一對嚴重的零日漏洞正席捲企業網絡,且攻擊者已在野外積極利用這些漏洞。這是一個 CVSS 評分高達 10.0 的漏洞鏈,猶如一張「免死金牌」,讓駭客能夠繞過身份驗證並以根權限(root-level)執行指令。

這些漏洞編號為 CVE-2026-15409CVE-2026-15410,它們並非僅存在於理論中。在 SonicWall 於 2026 年 7 月 14 日發布緊急修補程式之前,攻擊者已利用這些漏洞長達 22 天。Rapid7 MDR 團隊 發現 INC 勒索軟體組織正利用此漏洞鏈入侵企業環境。

技術分析:漏洞鏈運作原理

最令人頭痛的是 CVE-2026-15409。這是一個伺服器端請求偽造 (SSRF) 漏洞,允許未經身份驗證的攻擊者將請求直接隧道傳輸至本應鎖定在 localhost 介面上的服務。本質上,它誘騙設備與其內部的組件進行通訊——這些組件原本不應暴露於公共網際網路中。

但這僅是問題的一半。當結合 CVE-2026-15410 時,情況會從糟糕演變為災難。雖然第二個漏洞在技術上是設備管理控制台 (AMC) 中的本地權限提升 (LPE) 與身份驗證後代碼注入錯誤,但它卻是最後的關鍵。一旦攻擊者透過 SSRF 取得初步立足點,他們便會利用第二個漏洞提升權限,從而獲得對設備的完全根權限控制。

圖片來源:The Hacker News

以下是您所面臨問題的分析:

漏洞 類型 CVSS 評分 影響
CVE-2026-15409 SSRF 10.0 未經身份驗證存取 localhost 服務
CVE-2026-15410 代碼注入 / LPE 7.2 根權限指令執行

誰處於風險之中?

並非所有 SonicWall 設備都受到影響。此特定威脅僅限於 SMA 1000 系列。如果您使用的是標準防火牆或 SMA 100 系列,則暫無此特定漏洞的風險。然而,如果您正在運行以下任何設備,請務必立即對照 SonicWall PSIRT 公告 檢查您的韌體版本:

  • SMA 6210
  • SMA 7210
  • SMA 8200v

此次攻擊是更廣泛、更激進行動的一部分。由於這些漏洞繞過了身份驗證,因此攻擊過程極為隱蔽。它們在標準日誌中幾乎不留痕跡,使得事後取證變得極其困難。甚至美國網路安全與基礎設施安全局 (CISA) 也已將其列入「已知被利用漏洞」(KEV) 目錄中,這是一個強烈的信號,表明這絕非演習。

緩解措施:您現在需要做什麼

修復方法很簡單,但刻不容緩:更新。SonicWall 已於 2026 年 7 月 14 日發布了必要的更新。如果您尚未安裝,等於是敞開大門讓 INC 等組織長驅直入。

除了點擊「更新」按鈕外,您的安全團隊還需要進行主動排查。請仔細檢查 SMA 1000 系列的日誌,尋找任何異常活動——特別是在漏洞被利用的那 22 天窗口期內。留意任何對 localhost 服務的意外連線,或對設備管理控制台的任何未經授權的變更。

正如 The Hacker News 的報導所述,遠端存取設備是威脅行為者的「皇冠上的寶石」。它們旨在連接網際網路與您的內部網絡,這使其成為完美的攻擊目標。

為確保安全,請採取以下步驟:

  • 更新韌體: 立即升級至最新版本,沒有例外。
  • 限制存取: 不要將設備管理控制台暴露在外。僅允許受信任的內部 IP 位址進行存取。
  • 強制執行 MFA: 如果您沒有為每個會話(無論是管理員還是使用者)啟用多重身份驗證,那麼您的安全防護已經落後了。
  • 網絡分段: 如果設備不幸被入侵,您不希望攻擊者能輕易存取其他數據。網絡分段是您的最後一道防線。

此次事件再次提醒我們,面向邊緣的基礎設施是高風險領域。INC 勒索軟體組織正積極尋找未修補的系統,而修補漏洞的窗口正在迅速關閉。請查閱 SonicWall 官方 PSIRT 公告 以獲取所需的具體版本號,並立即更新您的系統。不要等到日誌顯示您已經遭到攻擊才採取行動。

V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 

Viktor Sokolov is a network engineer and protocol security researcher with deep expertise in how data travels across the internet and where it becomes vulnerable. He spent eight years working for a major internet service provider, gaining firsthand knowledge of traffic analysis, deep packet inspection, and ISP-level surveillance capabilities. Viktor holds multiple Cisco certifications (CCNP, CCIE) and a Master's degree in Telecommunications Engineering. His insider knowledge of ISP practices informs his passionate advocacy for VPN use and encrypted communications.

相關新聞

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks
OpenVPN vulnerabilities

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks

A 2026 security audit reveals many commercial VPNs use outdated, vulnerable OpenVPN versions. See which providers are leaving your data exposed to RCE attacks.

作者: James Okoro 2026年8月5日 4 分鐘閱讀
common.read_full_article
SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure
SonicWall VPN vulnerabilities

SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure

Hackers are exploiting SonicWall VPNs via CVE-2024-40766 and credential stuffing. Learn how to secure your enterprise infrastructure against these attacks.

作者: Viktor Sokolov 2026年8月4日 4 分鐘閱讀
common.read_full_article
Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack
npm supply chain attack

Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack

Amazon threat intelligence links North Korean hackers to malicious npm supply chain attacks. Discover how popular libraries like axios were weaponized.

作者: Elena Voss 2026年8月3日 4 分鐘閱讀
common.read_full_article
AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks
AWS threat intelligence

AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks

AWS threat report reveals North Korean hackers are poisoning open-source repositories to infiltrate cloud environments and harvest developer credentials.

作者: James Okoro 2026年8月2日 5 分鐘閱讀
common.read_full_article