High severity8.1NVD Advisory· Published Apr 7, 2022· Updated Jul 13, 2026
CVE-2021-46416
CVE-2021-46416
Description
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:sma:sunny_tripower_firmware:3.10.16.r:*:*:*:*:*:*:*
- SUNNY/SUNNY TRIPOWER 5.0description
- Range: 3.10.16.R
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/166670/SAM-SUNNY-TRIPOWER-5.0-Insecure-Direct-Object-Reference.htmlnvdExploitThird Party AdvisoryVDB Entry
- drive.google.com/drive/folders/1BPULhDC_g__seH_VnQlVtkrKdOLkXdzVnvdExploitThird Party Advisory
- www.sma.de/en/products/solarinverters/sunny-tripower-30-40-50-60.htmlnvdProductVendor Advisory
News mentions
0No linked articles in our index yet.