2021-36380 | Sunhillo SureLine networkDiag.cgi os command injection
CVSS Meta Temp Score | Current Exploit Price (≈) | CTI Interest Score |
---|---|---|
6.0 | $0-$5k | 0.07 |
A vulnerability was found in Sunhillo SureLine up to 8.7.0.1.0. It has been rated as critical. This issue affects an unknown functionality of the file /cgi/networkDiag.cgi. The manipulation of the argument ipAddr/dnsAddr
with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-78. Impacted is confidentiality, integrity, and availability. The summary by CVE is:
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
The weakness was released 08/14/2021. The advisory is shared at research.nccgroup.com. The identification of this vulnerability is CVE-2021-36380 since 07/12/2021. The exploitation is known to be easy. The attack can only be done within the local network. No form of authentication is needed for a successful exploitation. Technical details are known, but no exploit is available.
Upgrading to version 8.7.0.1.1 eliminates this vulnerability.
Vendor
Name
VulDB Meta Base Score: 6.3
VulDB Meta Temp Score: 6.0
VulDB Base Score: 6.3
VulDB Temp Score: 6.0
VulDB Vector: 🔒
VulDB Reliability: 🔍
AV | AC | Au | C | I | A |
---|---|---|---|---|---|
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
Vector | Complexity | Authentication | Confidentiality | Integrity | Availability |
---|---|---|---|---|---|
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Class: Privilege escalation
CWE: CWE-78
ATT&CK: Unknown
Local: No
Remote: Partially
Availability: 🔒
Status: Not defined
Price Prediction: 🔍
Current Price Estimation: 🔒
0-Day | unlock | unlock | unlock | unlock |
---|---|---|---|---|
Today | unlock | unlock | unlock | unlock |
Threat Intelligence
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍Recommended: Upgrade
Status: 🔍
0-Day Time: 🔒
Upgrade: SureLine 8.7.0.1.1
07/12/2021 CVE assigned
08/14/2021 Advisory disclosed
08/14/2021 VulDB entry created
08/18/2021 VulDB last updateAdvisory: research.nccgroup.com
Status: Confirmed
CVE: CVE-2021-36380 (🔒)
Created: 08/14/2021 10:53
Updated: 08/18/2021 13:39
Changes: (2) source_cve_assigned source_cve_nvd_summary
Complete: 🔍
Comments
Download it now for free!