Description
This module chains three issues in SonicWall SMA1000 appliances. An unauthenticated, absolute-form OPTIONS request makes the WorkPlace listener act as an unintended forward proxy (CVE-2026-83548). The module uses this access and a vendor-installed CouchDB update handler to obtain read and write access to loopback CouchDB (SMA1000-9427), then enables CouchDB's native Erlang query server and executes one command as the couchdb service account.
That command derives the appliance-local ctrl-service credential and invokes sysCtrl.execCmsSnmpTrap. A command injection in the SNMP trap script (CVE-2026-83549) executes the selected command as root.
The module attempts to restore the original CouchDB logger configuration, remove its injected INI data, disable the Erlang query server, and delete its randomized CouchDB documents. SonicWall fixed the issues in platform hotfixes 12.4.3-03526 and 12.5.0-02952.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/sonicwall/sma1000_couchdb_rcemsf undefined(sma1000_couchdb_rce) > show actions ...actions...msf undefined(sma1000_couchdb_rce) > set ACTION < action-name >msf undefined(sma1000_couchdb_rce) > show options ...show and set options...msf undefined(sma1000_couchdb_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub