


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file …
Published:
9 januari 2026 om 23:00:00
Alert date:
10 januari 2026 om 13:10:58
Source:
nvd.nist.gov
A security vulnerability has been identified in Sangfor Operation and Maintenance Management System up to version 3.0.8. The flaw affects an unknown function in the file /fort/trust/version/common/common.jsp, where manipulation of the File argument leads to unrestricted file upload capabilities. This vulnerability can be exploited remotely and a public exploit has been released. The vendor was notified about the disclosure but did not provide any response. The vulnerability poses significant risk due to its remote exploitability and public availability of exploit code.
Technical details
Mitigation steps:
Affected products:
Sangfor Operation and Maintenance Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-15503
https://github.com/master-abc/cve/issues/13
https://github.com/master-abc/cve/issues/13#issue-3770623333
https://vuldb.com/?ctiid.340348
https://vuldb.com/?id.340348
https://vuldb.com/?submit.727253
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
