An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://certvde.com/en/advisories/VDE-2025-066 |
![]() ![]() |
History
Wed, 27 Aug 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sma
Sma sunny Boy Sma sunny Boy 1.5 Sma sunny Boy 2.5 Sma sunny Boy 3.0 Sma sunny Boy 3.6 Sma sunny Boy 4.0 Sma sunny Boy 5.0 Sma sunny Boy 6.0 |
|
Vendors & Products |
Sma
Sma sunny Boy Sma sunny Boy 1.5 Sma sunny Boy 2.5 Sma sunny Boy 3.0 Sma sunny Boy 3.6 Sma sunny Boy 4.0 Sma sunny Boy 5.0 Sma sunny Boy 6.0 |
Wed, 27 Aug 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 27 Aug 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices. | |
Title | SMA: Directory Traversal in Sunny Boy <3.10.27.R | |
Weaknesses | CWE-23 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-08-27T08:00:35.837Z
Updated: 2025-08-27T16:18:45.427Z
Reserved: 2025-07-18T05:04:57.291Z
Link: CVE-2021-4459

Updated: 2025-08-27T16:15:34.955Z

Status : Awaiting Analysis
Published: 2025-08-27T08:15:31.937
Modified: 2025-08-29T16:24:09.860
Link: CVE-2021-4459

No data.