
SonicWall SSL-VPN RCE
SonicWall „Virtual Office“ SSL-VPN-Produkte enthalten eine uralte Version von Bash, die anfällig für ShellShock ist, und sind daher anfällig für nicht authentifizierte Remote-Codeausführung (als „nobody“-Benutzer) über die /cgi-bin/jarrewrite.sh-URL.

https://github.com/darrenmartyn/visualdoor
https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit