CVE-2021-36380
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Sunhillo SureLine OS Command Injection Vulnerablity
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 98% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
sunhillo: sureline
קישורים
- https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-… ExploitThird Party Advisory
- https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-… ExploitThird Party Advisory
- https://www.sunhillo.com/product/sureline/ Product
- https://www.sunhillo.com/product/sureline/ Product
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource