8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
OS command injection vulnerability in the uploadCN function of VersionController.java, allowing remote attackers to execute arbitrary commands
Basic Information
ID
CVE-2025-15499
Source
VulDB
Published
Jan 9, 2026 at 21:32
Modified
Jan 9, 2026 at 21:54
Affected Product
Vendor
Sangfor
Product
Operation and Maintenance Management System
Version
3.0.0
Affected Versions
Sangfor Operation and Maintenance Management System 3.0.0
Sangfor Operation and Maintenance Management System 3.0.1
Sangfor Operation and Maintenance Management System 3.0.2
Sangfor Operation and Maintenance Management System 3.0.3
Sangfor Operation and Maintenance Management System 3.0.4
Sangfor Operation and Maintenance Management System 3.0.5
Sangfor Operation and Maintenance Management System 3.0.6
Sangfor Operation and Maintenance Management System 3.0.7
Sangfor Operation and Maintenance Management System 3.0.8
Sangfor Operation and Maintenance Management System 3.0.1
Sangfor Operation and Maintenance Management System 3.0.2
Sangfor Operation and Maintenance Management System 3.0.3
Sangfor Operation and Maintenance Management System 3.0.4
Sangfor Operation and Maintenance Management System 3.0.5
Sangfor Operation and Maintenance Management System 3.0.6
Sangfor Operation and Maintenance Management System 3.0.7
Sangfor Operation and Maintenance Management System 3.0.8
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Sangfor
Product
Operation and Maintenance Management System
Version
3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8