peter bassill · operator
$ cve CVE-2021-46416 JSON

CVE-2021-46416 EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 4.3% (pctl 91)

Patch early

A public exploit exists.

Description

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS4.26% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-639
On CISA KEVno
Public exploityes
Published2022-04-07
Last modified2026-07-13

Affected (2)

VendorProduct
smasunny tripower
smasunny tripower firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD