top of page
perceptive_background_267k.jpg

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 21:04:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Network Infrastructure, Zero-Day Vulnerabilities

A critical OS command injection vulnerability has been identified in the Sangfor Operation and Maintenance Security Management System (OMSMSS) versions up to 3.0.13. The vulnerability resides in the function com.sbr.fort.foreignDP.DpLoginController within the /fort/portal_login file at the Login Endpoint. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary OS commands on the affected system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vendor was notified prior to disclosure but did not respond, leaving users without an official patch or mitigation guidance. This vulnerability poses a significant risk to organizations using the affected Sangfor security management product, particularly as it targets the login endpoint which is typically internet-facing. Users are advised to restrict access to the system and monitor for suspicious activity until a patch is available.

Technical details

Mitigation steps:

Affected products:

Sangfor Operation and Maintenance Security Management System up to 3.0.13

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page