SonicWall SMA 零日漏洞遭積極利用,企業基礎設施面臨未經授權的 Root 存取風險

SonicWall SMA zero-day CVE-2026-15409 CVE-2026-15410 enterprise network security unauthenticated root access
V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 
2026年7月23日
4 分鐘閱讀
SonicWall SMA 零日漏洞遭積極利用,企業基礎設施面臨未經授權的 Root 存取風險

TL;DR

• SonicWall SMA 1000 系列設備正遭受勒索軟體集團的積極攻擊。 • 攻擊者串聯兩個關鍵漏洞以獲取未經授權的 Root 控制權。 • CVE-2026-15409 (SSRF) 與 CVE-2026-15410 (權限提升) 正被利用。 • 'ROOTRUN' 與 'KNUCKLEBALL' 等惡意工具確保了持久的後門存取。 • 管理員必須立即檢查日誌並安裝緊急安全更新。

SonicWall SMA 零日漏洞遭積極利用,企業基礎設施面臨未經授權的 Root 存取風險

如果您正在使用 SonicWall SMA 1000 系列設備,請立即停下手邊工作並檢查您的日誌。網絡安全機構與研究人員已證實,兩個嚴重的零日漏洞——CVE-2026-15409 與 CVE-2026-15410——正遭到野外積極利用。這並非理論上的風險;攻擊者正利用這些漏洞繞過身份驗證、提升權限,並獲取企業網絡的完整 Root 級別控制權。

攻擊線索直指多個重量級駭客組織,包括 Inc 勒索軟體集團以及名為 UTA0533 的神秘攻擊者。自 2026 年 6 月 22 日首次發現異常以來,這些組織一直忙於部署自訂惡意軟體、竊取憑證,並在企業環境中進行橫向移動,彷彿掌控了整個系統。

攻擊剖析

整場攻擊始於 CVE-2026-15409,這是一個伺服器端請求偽造 (SSRF) 漏洞,其 CVSS 評分高達 10.0 分。這是一個典型的「門戶大開」場景。透過利用基於 WebSocket 的隧道技術,未經授權的攻擊者可以直接與設備 localhost 上的服務進行通訊。本質上,他們繞過了旨在防止內部管理介面暴露於公共網際網路的安全檢查。

一旦在邊界打開缺口,他們便會轉向 CVE-2026-15410。這是一個隱藏在 remove_hotfix 工作流程中的高嚴重性權限提升漏洞。這是一種路徑遍歷技巧,讓攻擊者能在幾個簡單步驟內從「網際網路陌生人」變身為「Root 級別管理員」。將這兩個漏洞串聯起來,等於將您整個基礎設施的鑰匙拱手讓人。

SonicWall SMA 零日漏洞遭積極利用,企業基礎設施面臨未經授權的 Root 存取風險

圖片來源:The Hacker News

誰在幕後操縱?目的為何?

Rapid7 MDR 團隊 在此事件中進行了大量調查,記錄了這些攻擊者不僅僅是入侵,更是在系統中「落地生根」。他們發現了一些惡意負載,包括 'ROOTRUN'(一個 setuid 二進位檔案,確保即使設備重啟也能保持 Root 存取權)以及 'KNUCKLEBALL'(一個旨在將惡意 Java Archive (JAR) 檔案注入系統的 Python 指令碼)。

攻擊工具包不僅於此,研究人員還發現了:

  • Suo5: 一種 HTTP 代理工具,能保持通訊隱蔽。
  • ORANGETAIL: 一個網頁 Shell,為遠端指令執行和檔案竊取提供了便捷介面。
  • 憑證竊取工具: 這些工具特別危險,專門針對會話資料庫和多重身份驗證 (MFA) 種子。

當 Inc 勒索軟體集團取得 MFA 種子時,您的二次驗證機制將形同虛設。他們利用這些權限來繪製您的網絡拓撲、竊取敏感資料,並為最終行動——大規模加密——做好準備。

漏洞細節

CVE 編號 類型 嚴重性 影響
CVE-2026-15409 SSRF 嚴重 (10.0) 未經授權的 localhost 隧道存取
CVE-2026-15410 權限提升 高 (7.2) Root 級別程式碼執行

如何加固您的網絡

CISA 已於 2026 年 7 月 14 日將這兩個漏洞列入其「已知被利用漏洞」(KEV) 目錄。如果您尚未修補,您的安全防護已嚴重落後。

SonicWall 已發布修補程式,您需要立即安裝。請前往 SonicWall 官方 PSIRT 公告 獲取適用於您的 SMA 1000 系列設備(特別是 6210、7210 和 8200v 型號)的修補程式。

您的緊急待辦事項:

  1. 盤點: 確認您網絡中確切的 SMA 1000 設備數量。
  2. 修補: 立即套用製造商提供的修補程式。
  3. 稽核: 仔細檢查系統日誌。尋找任何可疑活動——WebSocket 隧道嘗試或出現 'ROOTRUN' 等二進位檔案都是重大危險訊號。
  4. 重置: 如果您懷疑已經遭到入侵,請假設系統已完全失守。重置設備上的所有憑證,包括管理員密碼以及那些關鍵的 MFA 種子。

Volexity 記錄的代理方法 嚴正提醒我們,邊緣設備是現代網絡中最危險的故障點。將 SSRF 與路徑遍歷串聯起來是一種外科手術式的精準打擊,這是我們越來越常看到的戰術。

隨著研究人員持續追蹤 Inc 集團的新負載與演進戰術,情況仍在變化。不要等到收到勒索信才開始加固邊界。請務必更新設備、監控流量,並假設如果您已暴露,就已經有人在尋找入侵途徑。

V
Viktor Sokolov

Network Infrastructure & Protocol Security Researcher

 

Viktor Sokolov is a network engineer and protocol security researcher with deep expertise in how data travels across the internet and where it becomes vulnerable. He spent eight years working for a major internet service provider, gaining firsthand knowledge of traffic analysis, deep packet inspection, and ISP-level surveillance capabilities. Viktor holds multiple Cisco certifications (CCNP, CCIE) and a Master's degree in Telecommunications Engineering. His insider knowledge of ISP practices informs his passionate advocacy for VPN use and encrypted communications.

相關新聞

Qilin Ransomware Group Targets Enterprise VPN Infrastructure in Coordinated Attacks Against Major Network Vendors
Qilin ransomware

Qilin Ransomware Group Targets Enterprise VPN Infrastructure in Coordinated Attacks Against Major Network Vendors

Qilin ransomware is exploiting critical vulnerabilities in major VPN vendors. Learn how this RaaS group breaches networks and how to protect your infrastructure.

作者: Elena Voss 2026年7月28日 4 分鐘閱讀
common.read_full_article
State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy
MarkiRAT malware

State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

State-sponsored hackers are using fake VPN apps to deploy the MarkiRAT malware, targeting Persian speakers globally to steal sensitive data and monitor devices.

作者: James Okoro 2026年7月27日 4 分鐘閱讀
common.read_full_article
State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy
state-sponsored spyware

State-Sponsored Spyware Discovered in Malicious VPN Applications Targeting Global User Authentication and Privacy

Hackers are using trojanized VPN apps to steal private messages and monitor devices. Learn how Bahamut and TAG-182 spyware bypass security to compromise your data.

作者: Viktor Sokolov 2026年7月26日 5 分鐘閱讀
common.read_full_article
Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns
SonicWall SMA1000

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns

SonicWall SMA1000 appliances are under attack by UTA0533 using zero-day exploits. Patch immediately to prevent root-level access and data theft.

作者: Elena Voss 2026年7月25日 4 分鐘閱讀
common.read_full_article