EXPOSURES › CVE-2021-36380
CVE-2021-36380
HIGH ⌖ ON CISA KEV · EXPLOITEDSunhillo SureLine OS command injection allows attackers to execute arbitrary commands via shell metacharacters in network diagnostic inputs.
This OS command injection vulnerability in Sunhillo's SureLine allows attackers to execute arbitrary commands via shell metacharacters in ipAddr or dnsAddr fields within the /cgi/networkDiag.cgi endpoint, enabling persistence and denial-of-service. DIB organizations must patch immediately as this is actively exploited in the KEV list and poses a direct supply-chain risk for IoT devices.
Shame score — Active exploitation in KEV indicates negligence in patch management despite known vulnerability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.