Skip to finding
important · Edge — SonicWall

Public Metasploit code turns the SMA1000 WorkPlace service into a root session.

Affects

SonicWall Secure Mobile Access 1000 Series, internet-facing enterprise remote-access gateways.

An unauthenticated HTTPS request reaches loopback CouchDB, enables its Erlang query server, derives a DMI-based control credential and uses sed injection to execute a root command.

Detail and 6 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026