漏洞描述
Sunhillo SureLine <8.7.0.1.1 is vulnerable to OS command injection. The /cgi/networkDiag.cgi script directly incorporated user-controllable parameters within a shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. The following POST request injects a new command that instructs the server to establish a reverse TCP connection to another system, allowing the establishment of an interactive remote shell session.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
research.nccgroup.comhttps://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-unauthenticated-os-command-injection-cve-2021-36380/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-36380↗www.sunhillo.comhttps://www.sunhillo.com/product/sureline/↗github.comhttps://github.com/Ostorlab/KEV↗github.comhttps://github.com/fkie-cad/nvd-json-data-feeds↗