---
analysis: This hunt pivots between software inventory, traffic prevalence, and behavioural
  parent-child process relationships. A single detection rule might miss the chain
  if an adversary rotates URI paths, but this hunt correlates host vulnerability status
  with anomalous shell execution from management context.
blind_spots:
- id: appliance-log-visibility
  question: whether the command injection payload is directly visible in the web logs
  requires: hb_http_activity with full POST body logs from the appliance
  risk: Standard HTTP logs show the request path but may miss the actual payload if
    it is contained in the request body, leading to an incomplete view of the injection
    attempt.
  stage: initial-access-chained-vulnerability-exploitation
- id: restricted-shell-logging
  question: whether commands executed via the injection are visible if the appliance
    does not support standard process auditing
  requires: hb_process_activity from the appliance underlying OS
  risk: Proprietary appliances often restrict OS-level auditing; command execution
    might only be visible if the appliance forwards audit logs to a central collector.
  stage: execution-of-arbitrary-os-commands
coverage:
- stage: discovery-of-exposed-vulnerable-gateways
  status: covered
  steps:
  - scoping-vulnerable-appliances
- stage: initial-access-chained-vulnerability-exploitation
  status: covered
  steps:
  - prevalence-management-traffic
- stage: execution-of-arbitrary-os-commands
  status: covered
  steps:
  - behaviour-shell-execution
- reason: Not examined by this hunt; belongs to a separate hunt.
  stage: potential-credential-and-token-access
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: SonicWall SMA1000 appliances are critical edge gateways; unauthenticated
    RCE on these systems provides a direct path to internal networks. Active exploitation
    in the wild creates a high-risk exposure that justifies an estate-wide search.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is exploiting a chain of SSRF and command injection vulnerabilities
  on a SonicWall SMA1000 appliance to achieve remote code execution, indicated by
  rare HTTP management traffic followed by shell spawns from web processes.
labels:
- hunt
- attack.t1190
- attack.t1059
- credential access
- discovery
- execution
- initial access
name: SonicWall SMA1000 Edge Appliance Exploitation
parameters:
  lookback_days:
    default: '14'
    description: History to examine for exploitation signs.
    type: number
  scope_hosts:
    default: []
    description: Specific hostnames to focus on; leave empty to hunt across all discovered
      vulnerable appliances.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on internet-exposed SMA1000 appliances identified in the first step.
  Use the resulting hostnames to populate the scope_hosts parameter for traffic and
  process analysis.
references:
- name: "Rapid7 \u2014 Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548,\
    \ CVE-2026-83549 Exploited in the Wild"
  url: https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild
related:
- hunt: sma1000-post-exploitation-credential-access
  reason: Post-exploitation credential theft or token access requires different telemetry
    surfaces such as hb_auth_signin or hb_account_change which are out of scope for
    this initial RCE hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Discovery of exposed vulnerable gateways
    observables:
    - SonicWall SMA1000 Models 6210, 7210, 8200v
    - Versions 12.4.3-03453 and earlier
    - Versions 12.5.0-02835 and earlier
    - SMA1000 Appliance Work Place interface
    - Appliance Management Console (AMC)
    slug: discovery-of-exposed-vulnerable-gateways
    tactic: discovery
    techniques:
    - T1580
  - name: Initial access via chained RCE
    observables:
    - CVE-2026-83548 (SSRF)
    - CVE-2026-83549 (Command Injection)
    - Inbound requests to SMA1000 Appliance Work Place interface
    - Unauthenticated access to sensitive management functionality
    slug: initial-access-chained-vulnerability-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Execution of arbitrary OS commands
    observables:
    - Execution of arbitrary OS commands from the Appliance Management Console context
    - Commands spawning from the web server or appliance management processes
    slug: execution-of-arbitrary-os-commands
    tactic: execution
    techniques:
    - T1059
  - name: Potential credential and token access
    observables:
    - Unauthorized access to user and administrator passwords
    - Access to Time-based One-Time Password (TOTP) tokens
    slug: potential-credential-and-token-access
    tactic: credential-access
    techniques:
    - T1555
  summary: Attackers chain a critical SSRF vulnerability (CVE-2026-83548) and an OS
    command injection flaw (CVE-2026-83549) in SonicWall SMA1000 appliances to achieve
    unauthenticated remote code execution. This allows an external actor to execute
    arbitrary commands on the network edge and potentially access stored credentials
    or session tokens.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# SonicWall SMA1000 Edge Appliance Exploitation

This hunt identifies SonicWall SMA1000 appliances vulnerable to CVE-2026-83548 and CVE-2026-83549 and searches for evidence of post-exploitation activity. Because these appliances are network-edge systems, any unauthenticated access to the Work Place or Management Console followed by process execution is irregular. The hunt starts by scoping the estate via software inventory, stack-counts HTTP paths to management interfaces to identify anomalous access, and identifies shell execution originating from web-related parent processes. An agent correlates these signals to identify compromised appliances.

## scoping-vulnerable-appliances
<!-- Identify vulnerable SonicWall appliances -->
Find resources running vulnerable versions of SonicWall SMA1000 software to define the target scope.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames representing the potential attack surface. Silence indicates
  no SonicWall SMA1000 software was discovered.
reads:
- device_hostname
- package_name
- package_version
- vendor_name
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%sma1000%' OR LOWER(vendor_name) LIKE '%sonicwall%') AND (package_version <= '12.4.3-03453' OR package_version <= '12.5.0-02835')
```

## prevalence-management-traffic
<!-- Rare HTTP requests to appliance management paths -->
Stack-count HTTP request paths on the scoped hosts to find rare access to the Work Place or AMC interfaces, which may indicate SSRF or command injection attempts.

```sqlite target=web role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Unusual paths or parameters that differ from baseline administrative use.
  Fewer than 10 hits per host to management paths is a strong lead for unauthenticated
  exploitation.
prevalence:
  by: device_hostname
  key:
  - url_path
  rare_below: 10
reads:
- device_hostname
- url_path
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, url_path, COUNT(*) AS request_count, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%workplace%' OR LOWER(url_path) LIKE '%/amc/%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path HAVING request_count <= 10 ORDER BY request_count ASC
```

## behaviour-shell-execution
<!-- Shell execution from appliance management processes -->
Identify shells or interpreters spawning from web-facing or management processes, suggesting successful command injection.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Shell execution on a network appliance is highly irregular. If the parent
  process is a web server or management daemon, it directly suggests exploitation
  of CVE-2026-83549.
reads:
- device_hostname
- process_name
- process_cmd_line
- parent_process_name
- parent_process_cmd_line
- user_name
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, parent_process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%/nc' OR LOWER(process_name) LIKE '%/python%' OR LOWER(process_name) LIKE '%/perl%') AND (LOWER(parent_process_name) LIKE '%httpd%' OR LOWER(parent_process_name) LIKE '%nginx%' OR LOWER(parent_process_name) LIKE '%apache%' OR LOWER(parent_process_name) LIKE '%sonicwall%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC
```

## exploitation-triage
<!-- Assess exploitation evidence -->
```agent target=hunter
cite: required
context:
- scoping-vulnerable-appliances
- prevalence-management-traffic
- behaviour-shell-execution
max_iterations: 4
objective: Determine if any SonicWall SMA1000 appliance shows a chain of rare management
  traffic followed by shell execution from a web process context.
success_criteria: A verdict of malicious | suspicious | benign per host, citing specific
  process and HTTP rows.
tools:
- endpoint
- web
```

## verdict-route
<!-- Route on triage result -->
if~: "the exploitation-triage verdict is malicious or suspicious for at least one host" (confidence: high, judge=hunter)
then: → task-remediation-review
indeterminate: → task-remediation-review
unavailable: → task-remediation-review (blind_spot: appliance-log-visibility)
else: → task-close-out

## task-remediation-review
<!-- Analyze findings and coordinate patching -->
```manual target=analyst
Review the cited rows for evidence of RCE. Coordinate the application of SonicWall hotfixes (12.4.3-03526 or 12.5.0-02952). For appliances with confirmed suspicious activity, engage SonicWall Technical Support and plan to re-image hardware or re-deploy virtual instances as per vendor guidance.
```
→ end

## task-close-out
<!-- Close out hunt -->
```manual target=analyst
Record which appliances were checked and confirm if they are running fixed versions. If the estate remains vulnerable but clean, schedule a periodic re-run of this hunt until patching is verified.
```
→ end
