漏洞概述 Rapid7 MDR团队发现了两个正在被积极利用的SonicWall SMA1000系列远程访问设备的零日漏洞:CVE-2026-15409和CVE-2026-15410。 CVE-2026-15409:这是一个严重的服务器端请求伪造(SSRF)漏洞,CVSS评分为10.0。成功利用此漏洞允许未认证的攻击者打开一个基于websocket的隧道到任意本地回环服务。 CVE-2026-15410:这是一个本地权限提升漏洞,CVSS评分为8.0。允许具有访问监听在端口8188上的内部服务权限的攻击者通过恶意路径遍历执行任意操作系统命令。 这两个漏洞正在被积极利用,攻击者通过绕过传统输入验证控制来利用这些漏洞,从而获得对系统的控制权。 影响范围 受影响的SonicWall SMA1000系列设备包括型号6210、7210和8200v,运行以下版本: 12.4.3-03245 12.4.3-03387 12.4.3-03434 (platform-hotfix) 12.5.0-02283 12.5.0-02624 12.5.0-02800 (platform-hotfix) 这些漏洞不影响SonicWall防火墙或SMA 100系列产品的SSL VPN功能。 修复方案 组织应立即升级到最新的平台hotfix版本: SMA1000系列 (6210, 7210, 8200v):12.4.3-03453 (platform-hotfix) 或更高版本 SMA1000系列 (6210, 7210, 8200v):12.5.0-02835 (platform-hotfix) 或更高版本 由于已确认存在积极利用,组织不应仅依赖补丁。SonicWall还建议: 进行彻底的取证审查以查找妥协指标 如果确认妥协,重新映像物理设备或重新部署虚拟设备 更改用户和管理员密码 重置TOTP令牌 POC代码 以下是CVE-2026-15409的Python概念验证代码: 以下是利用CVE-2026-15410的示例恶意请求: 以下是系统监控(pspy)输出示例,显示利用过程中的行为: 观察到的利用 攻击者通过绕过传统输入验证控制来利用这些漏洞,从而获得对系统的控制权。一旦建立了立足点,攻击者系统地提取了高价值凭证、活动会话数据库和时间基于一次性密码(TOTP)多因素认证(MFA)种子配置。这些活动旨在确保长期、持久的威胁,能够生存标准的网络级补救措施。 指标和证据来源 Rapid7建议审查设备日志以查找积极利用的证据,包括以下特征行为和特定日志指标: WebSocket exploit IOC log patterns: extraweb_access.log entries containing the strings ("GET" AND "wsproxy" AND "+-3389" AND "101") indicate interactions with the niche affected service. Hotfix removal exploit IOC log patterns: The ctrl-service.log shows the hotfix-removal utility (/usr/local/bin/remove_hotfix) being invoked with traversal sequences pointing to attacker-staged shell script payloads. Internet-facing probing: Enumeration of the SMA portal, including repeated requests to /auth1.html, path-traversal attempts, and generic file/enumeration requests. Authentication activity: Authentication-API activity against /_api/_logon//authenticate. Sensitive path access: Access to sensitive appliance paths such as /tmp/temp.db, consistent with theft of stored session data. AD/Service Account Compromise: NTLM logons (Windows Event ID 4624, logon type 3) into internal domain controllers sourced from the appliance's internal IP address. extraweb_access.log: Requests to /_api/_login or /_api/_logout returning HTTP 200, and requests to /wsproxy containing suspicious host parameters returning HTTP 101. 配置工件 /var/lib/unit/conf.json containing routes for /_api/_login or /_api/_logout, which are not present in legitimate configurations. 原子指标 F.N.S Holdings Limited (ASN - 206092)**: The threat actor(s) utilized varying IP addresses, but they belonged to the VPN hosting provider FNS Holdings Limited. Limit or block access to FNS Holdings Limited if there is no business need. For reference, the IP addresses we observed were: - 45.131.194.0/24 - 45.146.54.0/24 - 63.135.161.0/24 - 172.239.211.0/24 - 193.37.32.[1]79 - 193.37.32.[2]14 - 216.73.163.[1]51 - 216.73.163.[1]58 如果识别出任何妥协指标,组织应将设备视为已妥协,并遵循SonicWall的恢复指南。 Rapid7客户 组织应优先识别所有面向互联网的SonicWall SMA1000设备,并确定是否已部署受影响的软件版本。鉴于SonicWall和Rapid7确认的积极利用,暴露的设备应被视为高优先级资产进行补救。 安全团队还应审查可用的身份验证、Web访问和设备管理日志,以确定是否需要后续事件响应活动。 曝光命令、InsightVM和Nexpose Exposure Command、InsightVM和Nexpose客户将能够评估对CVE-2026-15409和CVE-2026-15410的暴露,并在7月15日的内容发布中提供经过身份验证的漏洞检查。 更新 2026年7月15日:初始发布。 文章标签 Emergent Threat Response Labs Managed Detection and Response (MDR)