Executive brief
Sunhillo SureLine contains an unauthenticated OS command injection vulnerability in /cgi/networkDiag.cgi. Attackers can execute arbitrary commands via shell metacharacters in the ipAddr or dnsAddr parameters, potentially leading to full system compromise or denial-of-service.
Affected products
- Sunhillo SureLine before 8.7.0.1.1
Timeline
- 2021-07-26: disclosed: Technical advisory published by NCC Group
- 2021-08-13: advisory: NVD Published Date
- 2024-03-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog