CVE-2021-46416

HIGH

SUNNY TRIPOWER 5.0 - Info Disclosure

Title source: llm

Description

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

Exploits (1)

exploitdb WORKING POC
by Momen Eldawakhly · textwebappshardware
https://www.exploit-db.com/exploits/50860

Scores

CVSS v3 8.1
EPSS 0.0629
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-639
Status published
Products (1)
sma/sunny_tripower_firmware 3.10.16.r
Published Apr 07, 2022
Tracked Since Feb 18, 2026