ZeroHour

CVE-2021-46416

PoC ×2
CVSS 3.1
8.1 high
EPSS
4%p91
Published
()
Modified
Description

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

Vendors
sma
Products
sunny tripower firmware
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.