HTTP RULE(RULE ID:336215)

Rule General Information
Release Date: 2024-04-29
Rule Name: Sunlogin Remote Code Execution Vulnerability
Severity: Critical
CVE ID:
Rule Protection Details
Description: Sunlogin is a remote control software that can initiate multiple remote connections at the same time. Before its 11.0 version, there was a remote code execution vulnerability. An unauthenticated attacker can obtain a valid Cookie through the /cgi-bin/rpc port and execute remote commands through the Cookie.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.