SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution

zetlyn/cve-metasploit exploit cve CVE-2026-83548 cve CVE-2026-83549 known 2026-09-01

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/sonicwall_sma1000_couchdb_rce.rb

Properties

platformLinux,Unix
receipt
Source
Metasploit exploit modules
Its words
Linux,Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 15:23 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "sfewer-r7",
    "William Perry",
    "Adam Babis"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module chains three issues in SonicWall SMA1000 appliances. An\n          unauthenticated, absolute-form OPTIONS request makes the WorkPlace\n          listener act as an unintended forward proxy (CVE-2026-83548). The\n          module uses this access and a vendor-installed CouchDB update handler\n          to obtain read and write access to loopback CouchDB (SMA1000-9427),\n          then enables CouchDB's native Erlang query server and executes one\n          command as the couchdb service account.\n\n          That command derives the appliance-local ctrl-service credential and\n          invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap\n          script (CVE-2026-83549) executes the selected command as root.\n\n          The module attempts to restore the original CouchDB logger\n          configuration, remove its injected INI data, disable the Erlang query\n          server, and delete its randomized CouchDB documents. SonicWall fixed\n          the issues in platform hotfixes 12.4.3-03526 and 12.5.0-02952.",
  "disclosure_date": "2026-09-01",
  "fullname": "exploit/linux/http/sonicwall_sma1000_couchdb_rce",
  "is_install_path": true,
  "mod_time": "2026-09-09 15:07:31 +0000",
  "name": "SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "config-changes",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-service-restarts"
    ]
  },
  "path": "/modules/exploits/linux/http/sonicwall_sma1000_couchdb_rce.rb",
  "platform": "Linux,Unix",
  "post_auth": false,
  "rank": 500,
  "ref_name": "linux/http/sonicwall_sma1000_couchdb_rce",
  "references": [
    "CVE-2026-83548",
    "CVE-2026-83549",
    "URL-https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016",
    "URL-https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW",
    "URL-https://software.sonicwall.com/PFORMSMAHOTFIX/Documentation/TechNotepform-hotfix-12.5.0-02952.txt",
    "URL-https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Linux Command"
  ],
  "type": "exploit"
}
rank500
Great. Detects the target automatically, or uses an application-specific return address.
receipt
Source
Metasploit exploit modules
Its words
500
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 15:23 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "sfewer-r7",
    "William Perry",
    "Adam Babis"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module chains three issues in SonicWall SMA1000 appliances. An\n          unauthenticated, absolute-form OPTIONS request makes the WorkPlace\n          listener act as an unintended forward proxy (CVE-2026-83548). The\n          module uses this access and a vendor-installed CouchDB update handler\n          to obtain read and write access to loopback CouchDB (SMA1000-9427),\n          then enables CouchDB's native Erlang query server and executes one\n          command as the couchdb service account.\n\n          That command derives the appliance-local ctrl-service credential and\n          invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap\n          script (CVE-2026-83549) executes the selected command as root.\n\n          The module attempts to restore the original CouchDB logger\n          configuration, remove its injected INI data, disable the Erlang query\n          server, and delete its randomized CouchDB documents. SonicWall fixed\n          the issues in platform hotfixes 12.4.3-03526 and 12.5.0-02952.",
  "disclosure_date": "2026-09-01",
  "fullname": "exploit/linux/http/sonicwall_sma1000_couchdb_rce",
  "is_install_path": true,
  "mod_time": "2026-09-09 15:07:31 +0000",
  "name": "SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "config-changes",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-service-restarts"
    ]
  },
  "path": "/modules/exploits/linux/http/sonicwall_sma1000_couchdb_rce.rb",
  "platform": "Linux,Unix",
  "post_auth": false,
  "rank": 500,
  "ref_name": "linux/http/sonicwall_sma1000_couchdb_rce",
  "references": [
    "CVE-2026-83548",
    "CVE-2026-83549",
    "URL-https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016",
    "URL-https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW",
    "URL-https://software.sonicwall.com/PFORMSMAHOTFIX/Documentation/TechNotepform-hotfix-12.5.0-02952.txt",
    "URL-https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Linux Command"
  ],
  "type": "exploit"
}

Text

This module chains three issues in SonicWall SMA1000 appliances. An unauthenticated, absolute-form OPTIONS request makes the WorkPlace listener act as an unintended forward proxy (CVE-2026-83548). The module uses this access and a vendor-installed CouchDB update handler to obtain read and write access to loopback CouchDB (SMA1000-9427), then enables CouchDB's native Erlang query server and executes one command as the couchdb service account. That command derives the appliance-local ctrl-service credential and invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap script (CVE-2026-83549) executes the selected command as root. The module attempts to restore the original CouchDB logger configuration, remove its injected INI data, disable the Erlang query server, and delete its randomized CouchDB documents. SonicWall fixed the issues in platform hotfixes 12.4.3-03526 and 12.5.0-02952.