CVE-2021-36380: Sunhillo SureLine OS Command Injection Vulnerablity.
Sunhillo SureLine OS Command Injection Vulnerablity. Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.
- CISA KEV-listed (remediation due 2024-03-26)
- EPSS 93.6% (99.9% percentile)