SonicWall SMA1000 as an internal attack platform: SSRF to Erlang RCE, then DCSync straight off the appliance
Tradecraft from a real campaign. CVE-2026-15409 is an unauthenticated SSRF in the SMA1000 WorkPlace interface. The /wsproxy WebSocket endpoint reaches a locally bound Erlang node, you complete the distribution handshake with the hardcoded cookie, and os:cmd() gets command exec as couchdb. Rather than pivot to an internal host, the operator kept operations on the appliance. Read policy_file.xml for LDAP binds, decrypted them, dropped a Linux secretsdump build to /tmp and ran DCSync from the edge device itself. The strong version used domain-controller machine-account hashes recovered from LSA secrets for pass-the-hash, since DC computer accounts already hold replication rights. Living on the appliance means no EDR and very little logging on the box. The exploit is a refactor of Rapid7's PoC. Full chain and scripts in the post, for awareness and detection. https://hunt.io/blog/sonicwall-sma1000-uk-council-attack submitted by /u/Straight-Practice-99 [link] [comments]