CVE-2021-4459: SMA Boy 3.0
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.
Affected products
- SMA Boy 3.0: from 0.0.0, before 3.10.27.R (fixed in 3.10.27.R)
- SMA Boy 3.6: from 0.0.0, before 3.10.27.R (fixed in 3.10.27.R)
- SMA Boy 4.0: from 0.0.0, before 3.10.27.R (fixed in 3.10.27.R)
- SMA Boy 5.0: from 0.0.0, before 3.10.27.R (fixed in 3.10.27.R)
- SMA Boy 6.0: from 0.0.0, before 3.10.27.R (fixed in 3.10.27.R)
Published 2025-08-27. Last modified 2026-06-17.