S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-36380 Scanner

CVE-2021-36380 scanner - Command Injection vulnerability in Sunhillo SureLine

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-36380
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
surelineby sunhillo
AFFECTED< 8.7.0.1.1SAFE ✓≥ 8.7.0.1.1
Updated Aug 21, 2026View on NVD →
Detail

The Sunhillo SureLine is a network monitoring device used by organizations to diagnose issues with their network infrastructure. The device is designed to provide users with real-time network monitoring and management capabilities, allowing them to quickly identify and resolve network issues before they impact the operations of the organization. Additionally, Sunhillo SureLine allows users to collect and analyze network data, and generate reports to better understand network performance.

Recently, a vulnerability was detected in the Sunhillo SureLine device, identified as CVE-2021-36380. This vulnerability allows unauthenticated OS command injection via shell metacharacters in the ipAddr or dnsAddr /cgi/networkDiag.cgi, which can be exploited by attackers to execute malicious code on the device and take control of the network.

When exploited, this vulnerability can lead to a range of issues for organizations, including data breaches, network downtime, theft of sensitive information, and loss of reputation. Attackers can use the device to gain unauthorized access to sensitive information, spread malicious code across the network, and even launch attacks against other organizations connected to the same network.

In conclusion, it's essential to protect your digital assets from threats such as the CVE-2021-36380 vulnerability. With s4e.io, you can easily and quickly learn about vulnerabilities in your digital assets and take preventive measures to secure your network. Invest in the pro features of the s4e.io platform and keep your network safe and secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations should take the following precautions:

  • Apply the available patches: The Sunhillo SureLine device comes with an update mechanism, ensuring that users can apply the latest security patches and upgrades. Check for updates regularly and apply them as soon as they become available.
  • Restrict network access: Limit the number of devices connected to the network, and use appropriate access controls to restrict access to sensitive information and services.
  • Follow best security practices: Ensure that all your devices are configured and secured following the best security practices, including using strong passwords, limiting user access, and disabling unnecessary services.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-36380 scanner - Command Injection vulnerability in Sunhillo SureLine | S4E