AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2019-9161

CRITICAL · CVSS 9.8 EPSS 4.60% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-04-18 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-9161
Severity
CRITICAL
CVSS
9.8
EPSS
4.60%
Nginx

Original Filing — NVD Description

WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters in the nginx_webconsole.php Cookie header can be used to read an etc/config/wac/wns_cfg_admin_detail.xml file containing the admin password. (The password for root is the WebUI admin password concatenated with a static string.)