CVE 9.3 CRITICAL

Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection_CVE-2025-15501

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

AI Analysis

OS command injection vulnerability in Sangfor Operation and Maintenance Management System up to 3.0.8, allowing remote exploitation

Basic Information

ID CVE-2025-15501
Source VulDB
Published Jan 9, 2026 at 22:32

Affected Product

Vendor Sangfor
Product Operation and Maintenance Management System
Version 3.0.0
Affected Versions Sangfor Operation and Maintenance Management System 3.0.0
Sangfor Operation and Maintenance Management System 3.0.1
Sangfor Operation and Maintenance Management System 3.0.2
Sangfor Operation and Maintenance Management System 3.0.3
Sangfor Operation and Maintenance Management System 3.0.4
Sangfor Operation and Maintenance Management System 3.0.5
Sangfor Operation and Maintenance Management System 3.0.6
Sangfor Operation and Maintenance Management System 3.0.7
Sangfor Operation and Maintenance Management System 3.0.8

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Sangfor
Product Operation and Maintenance Management System
Version 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.