An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-066 |
|
History
Wed, 27 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sma
Sma sunny Boy Sma sunny Boy 1.5 Sma sunny Boy 2.5 Sma sunny Boy 3.0 Sma sunny Boy 3.6 Sma sunny Boy 4.0 Sma sunny Boy 5.0 Sma sunny Boy 6.0 |
|
| Vendors & Products |
Sma
Sma sunny Boy Sma sunny Boy 1.5 Sma sunny Boy 2.5 Sma sunny Boy 3.0 Sma sunny Boy 3.6 Sma sunny Boy 4.0 Sma sunny Boy 5.0 Sma sunny Boy 6.0 |
Wed, 27 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 Aug 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices. | |
| Title | SMA: Directory Traversal in Sunny Boy <3.10.27.R | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-08-27T08:00:35.837Z
Updated: 2025-08-27T16:18:45.427Z
Reserved: 2025-07-18T05:04:57.291Z
Link: CVE-2021-4459
Updated: 2025-08-27T16:15:34.955Z
Status : Awaiting Analysis
Published: 2025-08-27T08:15:31.937
Modified: 2025-08-29T16:24:09.860
Link: CVE-2021-4459
No data.