The plan was admirably wholesome: compare the security posture of various commercial SSL VPN vendors and publish a sensible ranking. The plan died, as plans do, when its author — a researcher writing on SCRT’s blog.scrt.ch — kept wandering off to hunt for actual vulnerabilities instead. One of his targets was SonicWall’s SMA 500, a device that seemed slightly less popular than rival products and, possibly for that reason, slightly less frequently mauled by researchers. The code’s general appearance, he writes, suggested the bugs were there, waiting with the patience of furniture. The flaws he found were patched in December 2024, and the write-up was delayed to land alongside his talk at SecurityFest.
SonicWall hands out trial virtual machines from its own website, which is helpful of it, so the target was version 10.2.1.13-72sv, the latest available at the time. Booted up, the appliance exposed only ports 80 and 443, and its console offered a command-line interface with no obvious route to a shell. Getting a shell was job one, since a shell means you can extract the file system and debug the appliance while it squirms.
For this the researcher used a trick a former colleague had shown him, and it deserves to be savored for its absurd simplicity: pause the virtual machine, rummage through its saved memory file for the exact text of an operating-system command the CLI is known to invoke, replace that text with the command you’d prefer — keeping the byte count identical — resume the machine, and politely ask the CLI to do its job. The victim was the “Restart SSL VPN Services” menu option, which calls /usr/src/EasyAccess/bin/EasyAccessCtrl restart. That string was rewritten in memory to /////////////////////////////////////bin/bash — a staircase of forward slashes leading down to a root shell. Resume VM, click “restart,” and the appliance restarts nothing at all beyond your control of it.
From inside, netstat showed only two processes accepting connections: Apache on ports 80 and 443, and a Flask API listening on 127.0.0.1:12345 — a Python authentication service, reachable only from the appliance itself. Since Apache was the public face, the researcher read its configuration and found it vulnerable to an Apache path-confusion issue presented by Orange Tsai at Black Hat last year — a quirk that, in certain configurations, lets Apache be tricked into serving files from outside the web root. One particular RewriteRule in the SMA’s config, matching URLs of an IP-and-version-flavored .css pattern, had everything the trick needed.
Checking is trivially easy: request fileshare.10.1.2.13-72sv.css and fileshare.css%3f10.1.2.13-72sv.css from the target, and if the contents are identical, the door is ajar. The researcher’s first instinct was to read /etc/passwd, the traditional loot, but some other protection blocks any URL beginning with /etc. No great loss — the interesting files live in /tmp and /usr/src/EasyAccess. Especially interesting: /tmp/temp.db, an SQLite database containing the session identifiers of any logged-in user. Read that file, wait for a user to sign in, and you can simply borrow their session — account compromise by patience.
Impactful as that was, the researcher was really there for memory corruption, so he turned to the CGI binaries the web server exposes. A checksec pass showed partial protections: PIE notably absent, many binaries unfortified. He wrote a Ghidra-based script to flag dangerous functions — your strcpy and sprintf, the classics — and a second script to map links between binaries, both published alongside the post.
The dragnet surfaced numerous problems. In the sonicfiles CGI, for instance, the code allocates 0x80 bytes on the heap and then copies into it up to 0x400 bytes taken from a user-supplied parameter — an upsettingly plain heap overflow, “a straightforward heap overflow if I’ve ever seen one,” he writes, before adding, heroically honest, “heap exploitation is not my forte.” That one requires authentication, which dulled its appeal. He also found multiple stack-based buffer overflows, including one reachable without any login at all, in the cifsnavigate CGI — the kind of finding that vendors patch in December and researchers present on stage the following year.

