netVigilance Vulnerability intelligence since 2004
CVE-2021-36380 · netVigilance record NV24-0032

Sunhillo SureLine OS Command Injection Vulnerablity

past due

What to do

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA deadline 2024-03-26 · passed 2 years 5 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA

What happened

Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.

Who is affected

Sunhillo SureLine. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.

Weakness class: CWE-78.

Timeline

  1. Added to CISA KEVExploitation in the wild confirmed by CISA
  2. CISA remediation deadlinepassed 2 years 5 months ago

Sources