Skip to content

Known CVE

Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection

Sunhillo SureLine <8.7.0.1.1 is vulnerable to OS command injection. The /cgi/networkDiag.cgi script directly incorporated user-controllable parameters within a shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. The following POST request injects a new command that instructs the server to establish a reverse TCP connection to another system, allowing the establishment of an interactive remote shell session.

CVE-2021-36380

Critical2021CVSS 9.8CWE-78

cve2021 · sureline · rce · oast · sunhillo · kev · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website