Junglewise Threat Intelligence

CVE-2021-36380: Sunhillo SureLine OS Command Injection Vulnerablity

CVE-2021-36380 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-03-05

Executive brief

Sunhillo SureLine contains an unauthenticated OS command injection vulnerability in /cgi/networkDiag.cgi. Attackers can execute arbitrary commands via shell metacharacters in the ipAddr or dnsAddr parameters, potentially leading to full system compromise or denial-of-service.

Affected products

  • Sunhillo SureLine before 8.7.0.1.1

Timeline

  • 2021-07-26: disclosed: Technical advisory published by NCC Group
  • 2021-08-13: advisory: NVD Published Date
  • 2024-03-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog