SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution
zetlyn/cve-metasploit exploit cve CVE-2026-83548 cve CVE-2026-83549 known 2026-09-01
Properties
| platform | Linux,Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"sfewer-r7",
"William Perry",
"Adam Babis"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module chains three issues in SonicWall SMA1000 appliances. An\n unauthenticated, absolute-form OPTIONS request makes the WorkPlace\n listener act as an unintended forward proxy (CVE-2026-83548). The\n module uses this access and a vendor-installed CouchDB update handler\n to obtain read and write access to loopback CouchDB (SMA1000-9427),\n then enables CouchDB's native Erlang query server and executes one\n command as the couchdb service account.\n\n That command derives the appliance-local ctrl-service credential and\n invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap\n script (CVE-2026-83549) executes the selected command as root.\n\n The module attempts to restore the original CouchDB logger\n configuration, remove its injected INI data, disable the Erlang query\n server, and delete its randomized CouchDB documents. SonicWall fixed\n the issues in platform hotfixes 12.4.3-03526 and 12.5.0-02952.",
"disclosure_date": "2026-09-01",
"fullname": "exploit/linux/http/sonicwall_sma1000_couchdb_rce",
"is_install_path": true,
"mod_time": "2026-09-09 15:07:31 +0000",
"name": "SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"config-changes",
"ioc-in-logs"
],
"Stability": [
"crash-service-restarts"
]
},
"path": "/modules/exploits/linux/http/sonicwall_sma1000_couchdb_rce.rb",
"platform": "Linux,Unix",
"post_auth": false,
"rank": 500,
"ref_name": "linux/http/sonicwall_sma1000_couchdb_rce",
"references": [
"CVE-2026-83548",
"CVE-2026-83549",
"URL-https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016",
"URL-https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW",
"URL-https://software.sonicwall.com/PFORMSMAHOTFIX/Documentation/TechNotepform-hotfix-12.5.0-02952.txt",
"URL-https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/"
],
"rport": 443,
"session_types": false,
"targets": [
"Linux Command"
],
"type": "exploit"
} |
|---|---|
| rank | 500 Great. Detects the target automatically, or uses an application-specific return address. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"sfewer-r7",
"William Perry",
"Adam Babis"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module chains three issues in SonicWall SMA1000 appliances. An\n unauthenticated, absolute-form OPTIONS request makes the WorkPlace\n listener act as an unintended forward proxy (CVE-2026-83548). The\n module uses this access and a vendor-installed CouchDB update handler\n to obtain read and write access to loopback CouchDB (SMA1000-9427),\n then enables CouchDB's native Erlang query server and executes one\n command as the couchdb service account.\n\n That command derives the appliance-local ctrl-service credential and\n invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap\n script (CVE-2026-83549) executes the selected command as root.\n\n The module attempts to restore the original CouchDB logger\n configuration, remove its injected INI data, disable the Erlang query\n server, and delete its randomized CouchDB documents. SonicWall fixed\n the issues in platform hotfixes 12.4.3-03526 and 12.5.0-02952.",
"disclosure_date": "2026-09-01",
"fullname": "exploit/linux/http/sonicwall_sma1000_couchdb_rce",
"is_install_path": true,
"mod_time": "2026-09-09 15:07:31 +0000",
"name": "SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"config-changes",
"ioc-in-logs"
],
"Stability": [
"crash-service-restarts"
]
},
"path": "/modules/exploits/linux/http/sonicwall_sma1000_couchdb_rce.rb",
"platform": "Linux,Unix",
"post_auth": false,
"rank": 500,
"ref_name": "linux/http/sonicwall_sma1000_couchdb_rce",
"references": [
"CVE-2026-83548",
"CVE-2026-83549",
"URL-https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016",
"URL-https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW",
"URL-https://software.sonicwall.com/PFORMSMAHOTFIX/Documentation/TechNotepform-hotfix-12.5.0-02952.txt",
"URL-https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/"
],
"rport": 443,
"session_types": false,
"targets": [
"Linux Command"
],
"type": "exploit"
} |
Text
This module chains three issues in SonicWall SMA1000 appliances. An
unauthenticated, absolute-form OPTIONS request makes the WorkPlace
listener act as an unintended forward proxy (CVE-2026-83548). The
module uses this access and a vendor-installed CouchDB update handler
to obtain read and write access to loopback CouchDB (SMA1000-9427),
then enables CouchDB's native Erlang query server and executes one
command as the couchdb service account.
That command derives the appliance-local ctrl-service credential and
invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap
script (CVE-2026-83549) executes the selected command as root.
The module attempts to restore the original CouchDB logger
configuration, remove its injected INI data, disable the Erlang query
server, and delete its randomized CouchDB documents. SonicWall fixed
the issues in platform hotfixes 12.4.3-03526 and 12.5.0-02952.