CVE detail
CVE-2021-36380 — Sunhillo SureLine OS Command Injection Vulnerablity
Published 2024-03-05 · Modified 2024-03-05 · Source kev
HIGH
severity
CVSS-derived band
0.9760
EPSS probability
exploitation probability, 30d
100.0%
EPSS percentile
percentile vs all CVEs
LISTED
CISA KEV
due 2024-03-26
⚠ Actively exploited in the wild — CISA KEV listed 2024-03-05, federal remediation due 2024-03-26.
Description
Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References