CVE-2021-4459

MEDIUM

SMA Sunny Boy < 3.10.27.R - Authenticated Path Traversal

Title source: llm
STIX 2.1

Description

An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0062
EPSS Percentile 44.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-23
Status published
Products (5)
SMA/Boy 3.0 0.0.0 - 3.10.27.R
SMA/Boy 3.6 0.0.0 - 3.10.27.R
SMA/Boy 4.0 0.0.0 - 3.10.27.R
SMA/Boy 5.0 0.0.0 - 3.10.27.R
SMA/Boy 6.0 0.0.0 - 3.10.27.R
Published Aug 27, 2025
Tracked Since Feb 18, 2026