CVE-2021-36380
KEV PoC nicheUnauthenticated OS Command Injection in Sunhillo SureLine
CISA: Sunhillo SureLine OS Command Injection Vulnerablity
Sunhillo SureLine before version 8.7.0.1.1 contains an unauthenticated OS command injection flaw (CWE-78) in its /cgi/networkDiag.cgi web endpoint. An attacker with network access to the device's management interface can inject shell metacharacters into the ipAddr or dnsAddr parameters, causing arbitrary operating system commands to be executed with the privileges of the web service. Because no authentication or user interaction is required (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), a remote attacker can achieve full command execution, with high impact on confidentiality, integrity, and availability of the device. SureLine is Sunhillo's surveillance data distribution platform used primarily in the aviation sector (airports and air traffic control facilities), so affected users are mainly those organizations rather than the general public. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2024-03-05, indicating it has been observed being exploited in the wild, and a public technical advisory with a proof of concept was published by NCC Group in July 2021.
What to do: Upgrade SureLine to version 8.7.0.1.1 or later. If upgrading is not immediately possible, restrict network access to the device's management interface (especially the /cgi/networkDiag.cgi endpoint) and place the unit behind a firewall or VPN rather than exposing it directly to the internet. Note that as a KEV-listed vulnerability, CISA requires applying vendor mitigations or discontinuing use of the product, so inventory any internet-exposed SureLine appliances and check logs for unexpected requests to networkDiag.cgi.
| Sunhillo SureLine | All versions before 8.7.0.1.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
- Affected
- Sunhillo SureLine
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sunhillo
- Products
- sureline
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H