ZeroHour

CVE-2021-36380

KEV PoC niche

Unauthenticated OS Command Injection in Sunhillo SureLine

CISA: Sunhillo SureLine OS Command Injection Vulnerablity

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

Sunhillo SureLine before version 8.7.0.1.1 contains an unauthenticated OS command injection flaw (CWE-78) in its /cgi/networkDiag.cgi web endpoint. An attacker with network access to the device's management interface can inject shell metacharacters into the ipAddr or dnsAddr parameters, causing arbitrary operating system commands to be executed with the privileges of the web service. Because no authentication or user interaction is required (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), a remote attacker can achieve full command execution, with high impact on confidentiality, integrity, and availability of the device. SureLine is Sunhillo's surveillance data distribution platform used primarily in the aviation sector (airports and air traffic control facilities), so affected users are mainly those organizations rather than the general public. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2024-03-05, indicating it has been observed being exploited in the wild, and a public technical advisory with a proof of concept was published by NCC Group in July 2021.

What to do: Upgrade SureLine to version 8.7.0.1.1 or later. If upgrading is not immediately possible, restrict network access to the device's management interface (especially the /cgi/networkDiag.cgi endpoint) and place the unit behind a firewall or VPN rather than exposing it directly to the internet. Note that as a KEV-listed vulnerability, CISA requires applying vendor mitigations or discontinuing use of the product, so inventory any internet-exposed SureLine appliances and check logs for unexpected requests to networkDiag.cgi.

Affected
Sunhillo SureLineAll versions before 8.7.0.1.1
Estimated exposure
nichelikely hundreds to a few thousand deployments worldwide, concentrated in the aviation sector (unknown exact count) — SureLine is Sunhillo's surveillance data distribution product deployed mainly at airports and air traffic control facilities, a niche vertical with a small installed base, and only a fraction of those units are typically exposed to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.

CISA Known Exploited Vulnerability
Affected
Sunhillo SureLine
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sunhillo
Products
sureline
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news