
SonicWall SSL-VPN RCE
SonicWall “Virtual Office” SSL-VPN 제품군에는 ShellShock에 취약한 오래된 버전의 Bash가 포함되어 있으며, 따라서 /cgi-bin/jarrewrite.sh URL을 통해 인증되지 않은 원격 코드 실행("nobody" 사용자 권한)에 취약합니다.

https://github.com/darrenmartyn/visualdoor
https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit