Skip to content
COOEY

EXPOSURES › CVE-2021-36380

CVE-2021-36380

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-03-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-36380 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatchedsupply-chain

Sunhillo SureLine OS command injection allows attackers to execute arbitrary commands via shell metacharacters in network diagnostic inputs.

This OS command injection vulnerability in Sunhillo's SureLine allows attackers to execute arbitrary commands via shell metacharacters in ipAddr or dnsAddr fields within the /cgi/networkDiag.cgi endpoint, enabling persistence and denial-of-service. DIB organizations must patch immediately as this is actively exploited in the KEV list and poses a direct supply-chain risk for IoT devices.

Shame score — Active exploitation in KEV indicates negligence in patch management despite known vulnerability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.