CyberRota
Live Feed
Return to register
Case File

CVE-2016-9682

CRITICAL · CVSS 9.8 EPSS 23.30% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-02-22 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2016-9682
Severity
CRITICAL
CVSS
9.8
EPSS
23.30%

Original Filing — NVD Description

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn't properly escape the information passed in the 'tsrDeleteRestartedFile' or 'currentTSREmailTo' variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.