RULE(RULE ID:333872)

Rule General Information
Release Date: 2021-07-27
Rule Name: Sunhillo SureLine OS Command Injection Vulnerability (CVE-2021-36380)
Severity:
CVE ID:
Rule Protection Details
Description: Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://www.cybersecurity-help.cz/vdb/SB2021072802
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-unauthenticated-os-command-injection-cve-2021-36380/