---
id: CVE-2019-13529
title: >-
  An attacker could send a malicious link to an authenticated operator, which
  may allow remote attackers to perform actions with the permissions of the user
  on the Sunny WebBox Firmware Version 1.6 and prior
summary: >-
  An attacker could send a malicious link to an authenticated operator, which
  may allow remote attackers to perform actions with the permissions of the user
  on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP
  addresses …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-352
  - CWE-352
vendor: sma
product: sunny_webbox_firmware
affected:
  - sunny_webbox_firmware <= 1.6
published: '2019-10-09'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-13529'
references:
  - url: >-
      http://packetstormsecurity.com/files/154789/SMA-Solar-Technology-AG-Sunny-WebBox-1.6-Cross-Site-Request-Forgery.html
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.us-cert.gov/ics/advisories/icsa-19-281-01'
    label: ics-cert@hq.dhs.gov
  - url: >-
      http://packetstormsecurity.com/files/154789/SMA-Solar-Technology-AG-Sunny-WebBox-1.6-Cross-Site-Request-Forgery.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.us-cert.gov/ics/advisories/icsa-19-281-01'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://packetstorm.news/files/id/154789'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.03113
epssPercentile: 0.87273
exploitAvailable: true
ingestedAt: '2026-07-13T17:27:58.673Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-26T09:05:25.559Z'
---

## Overview

An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.

## Affected

- `sunny_webbox_firmware <= 1.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
