peter bassill · operator
$ cve CVE-2016-9683 JSON

CVE-2016-9683 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 11.6% (pctl 96)

Patch early

A public exploit exists.

Description

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal configurations. The CGI application doesn't properly escape the information it's passed when processing a particular multi-part form request involving scripts. The filename of the 'scriptname' variable is read in unsanitized before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. This is SonicWall Issue ID 181195.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS11.55% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploityes
Published2017-02-22
Last modified2026-06-17

Affected (1)

VendorProduct
dellsonicwall secure remote access server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD