File Access Vulnerability in Sunny Boy Devices by SMA Solar Technology
CVE-2021-4459

6.5MEDIUM

Key Information:

Vendor

Sma

Status
Vendor
CVE Published:
27 August 2025

What is CVE-2021-4459?

An authorized remote attacker can exploit a design flaw in the Sunny Boy devices by SMA Solar Technology, which allows them to access files and directories outside the designated web root. This unauthorized access could result in the exposure of sensitive system information, posing security risks and potential data breaches for users.

Affected Version(s)

Boy 3.0 0.0.0 < 3.10.27.R

Boy 3.6 0.0.0 < 3.10.27.R

Boy 4.0 0.0.0 < 3.10.27.R

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Alroky from KOIN Network
.
CVE-2021-4459 : File Access Vulnerability in Sunny Boy Devices by SMA Solar Technology