Vulnerability record · CVE-2021-36380 · published 13 August 2021
CVE-2021-36380: Sunhillo SureLine unauthenticated OS command injection in networkDiag.cgi
Sunhillo · Sureline
Sunhillo SureLine before 8.7.0.1.1 fails to sanitize shell metacharacters in the ipAddr and dnsAddr parameters handled by /cgi/networkDiag.cgi, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the CGI can run commands on the appliance.
Description
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a 9.8 CVSS score, KEV listing and near-maximum EPSS makes this an urgent patch-or-isolate case.
What it is
Sunhillo SureLine before 8.7.0.1.1 fails to sanitize shell metacharacters in the ipAddr and dnsAddr parameters handled by /cgi/networkDiag.cgi, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the CGI can run commands on the appliance.
Impact
An attacker gains arbitrary command execution with the privileges of the web service, enabling full compromise of the SureLine host and any data or network position it holds.
Attack surface
Reached over the network via HTTP requests to /cgi/networkDiag.cgi with crafted ipAddr or dnsAddr values; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and description confirm no authentication or user interaction is required.
Exploitation
CISA added it to KEV on 2024-03-05 with a 2024-03-26 remediation due date, and EPSS is 0.976 (99.9th percentile); NCC Group published a technical advisory tagged Exploit, so public exploitation is established.
What to do
- Upgrade SureLine to 8.7.0.1.1 or later; if no fixed version is available, discontinue use per CISA guidance.
- Restrict network access to the SureLine management/CGI interface to trusted administrative networks only.
- Place the appliance behind a reverse proxy or WAF that blocks shell metacharacters in ipAddr and dnsAddr parameters.
- Rotate credentials and review the host for persistence if compromise is suspected.
Detection
- Monitor web logs for requests to /cgi/networkDiag.cgi containing shell metacharacters (;, |, $(), backticks) in ipAddr or dnsAddr.
- Alert on unexpected child processes spawned by the SureLine web service (e.g., sh, bash, curl, wget).
- Hunt for outbound connections from the SureLine host to unfamiliar IPs or download activity following CGI requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-36380 to the Known Exploited Vulnerabilities catalog on 5 March 2024 as "Sunhillo SureLine OS Command Injection Vulnerablity". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 26 March 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-unauthenticated-os-command-injection-cve-2 | ExploitThird Party Advisory |
| https://www.sunhillo.com/product/sureline/ | Product |
| https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-unauthenticated-os-command-injection-cve-2 | ExploitThird Party Advisory |
| https://www.sunhillo.com/product/sureline/ | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36380 | US Government Resource |
Track CVE-2021-36380 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-36380), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.