EIP-2026-100901
PRE-CVESonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100901. PoCs published by xort.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Sonicwall SRA appliances (v8.1.0.2-14sv and earlier) via the gencsr CGI endpoint. It authenticates with provided credentials, injects commands through the 'key_size' parameter, and can execute arbitrary commands or deploy a payload.
Description
Sonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit)
Exploits (1)
This Metasploit module exploits a command injection vulnerability in Sonicwall SRA appliances (v8.1.0.2-14sv and earlier) via the gencsr CGI endpoint. It authenticates with provided credentials, injects commands through the 'key_size' parameter, and can execute arbitrary commands or deploy a payload.