{"id":"CVE-2021-46416","title":"Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.","summary":"Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-639","CWE-639"],"vendor":"sma","product":"sunny_tripower_firmware","affected":["sunny_tripower_firmware = 3.10.16.r"],"published":"2022-04-07","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-46416","references":[{"url":"http://packetstormsecurity.com/files/166670/SAM-SUNNY-TRIPOWER-5.0-Insecure-Direct-Object-Reference.html","label":"cve@mitre.org"},{"url":"https://drive.google.com/drive/folders/1BPULhDC_g__seH_VnQlVtkrKdOLkXdzV?usp=sharing","label":"cve@mitre.org"},{"url":"https://www.sma.de/en/products/solarinverters/sunny-tripower-30-40-50-60.html","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/166670/SAM-SUNNY-TRIPOWER-5.0-Insecure-Direct-Object-Reference.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://drive.google.com/drive/folders/1BPULhDC_g__seH_VnQlVtkrKdOLkXdzV?usp=sharing","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.sma.de/en/products/solarinverters/sunny-tripower-30-40-50-60.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/166670/SAM-SUNNY-TRIPOWER-5.0-Insecure-Direct-Object-Reference.html","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.04262,"epssPercentile":0.90638,"exploitAvailable":true,"ingestedAt":"2026-07-13T17:27:58.698Z","exploits":{"exploitdb":true,"checkedAt":"2026-09-24T07:52:48.932Z"},"slug":"CVE-2021-46416","body":"## Overview\n\nInsecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.\n\n## Affected\n\n- `sunny_tripower_firmware = 3.10.16.r`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.9,"exploitation":12,"ransomware":0},"changes":[]}