MEDIUM🇬🇧 English

CVE-2025-15502

CVSS 5.5v4.0pub. 2026-01-10upd. 2026-04-29

W Sangfor Operation and Maintenance Management System do wersji 3.0.8 zidentyfikowano podatność. Podatny element to funkcja SessionController w pliku /isomp-protocol/protocol/session, gdzie manipulacja parametrem Hostname prowadzi do os command injection. Atak może być wykonany zdalnie, a exploit jest publicznie dostępny. Vendor został powiadomiony wcześnie, ale nie odpowiedział.

Pokaż oryginał (EN)

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sangfor Operation And Maintenance Security Management System

    APP
    Sangfor
    ≤ 3.0.8
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2026-1324HIGH7.4ten sam produkt

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected b...

CVE-2025-15501HIGH8.9ten sam produkt

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is...

CVE-2026-1412MEDIUM5.5ten sam produkt

W Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto podatność. Zagrożona j...

CVE-2026-1325MEDIUM5.5ten sam produkt

W systemie Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto lukę bezpiecz...

CVE-2025-15503MEDIUM5.5ten sam produkt

W Sangfor Operation and Maintenance Management System do wersji 3.0.8 odkryto lukę bezpieczeństwa. Podatny ele...