{"id":"CVE-2021-36380","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-36380","summary":"Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.","details":"Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.","published":"2021-08-13T16:15:07.607","modified":"2026-06-17T03:58:46.613","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.97599,"percentile":0.99898,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":3,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-unauthenticated-os-command-injection-cve-2021-36380/"},{"type":"WEB","url":"https://www.sunhillo.com/product/sureline/"},{"type":"EXPLOIT","url":"https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-unauthenticated-os-command-injection-cve-2021-36380/"},{"type":"WEB","url":"https://www.sunhillo.com/product/sureline/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36380"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T03:58:46.613"}}