important · Edge — SonicWall
Public Metasploit code turns the SMA1000 WorkPlace service into a root session.
Affects
SonicWall Secure Mobile Access 1000 Series, internet-facing enterprise remote-access gateways.
An unauthenticated HTTPS request reaches loopback CouchDB, enables its Erlang query server, derives a DMI-based control credential and uses sed injection to execute a root command.
Detail and 6 sources
Rapid7 recorded uid=0 on a stock SMA8200v.
The module's failed test against build 12.4.3-02401 means not every older build is demonstrated chainable; the vendor has published fixed branch boundaries.
Sources
ResearchSecurity AdvisoryResearchhttps://tenable.com/plugins/nessus/342663ResearchCVE-2026-83548: Server-Side Request Forgery (SSRF) | Rapid7 Vulnerability DatabaseCode / PoCSonicWall SMA1000 unauthenticated RCE (CVE-2026-83548 + SMA1000-9427 + CVE-2026-83549) by sfewer-r7 · Pull Request #21883 · rapid7/metasploit-framework · GitHubCode / PoCmetasploit-framework/modules/exploits/linux/http/sonicwall_sma1000_couchdb_rce.rb at master · rapid7/metasploit-framework · GitHubCode / PoCmetasploit-framework/documentation/modules/exploit/linux/http/sonicwall_sma1000_couchdb_rce.md at master · rapid7/metasploit-framework · GitHub