9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
OS command injection vulnerability in Sangfor Operation and Maintenance Management System via HTTP POST Request Handler
Basic Information
ID
CVE-2025-15500
Source
VulDB
Published
Jan 9, 2026 at 21:32
Modified
Jan 9, 2026 at 21:53
Affected Product
Vendor
Sangfor
Product
Operation and Maintenance Management System
Version
3.0.0
Affected Versions
Sangfor Operation and Maintenance Management System 3.0.0
Sangfor Operation and Maintenance Management System 3.0.1
Sangfor Operation and Maintenance Management System 3.0.2
Sangfor Operation and Maintenance Management System 3.0.3
Sangfor Operation and Maintenance Management System 3.0.4
Sangfor Operation and Maintenance Management System 3.0.5
Sangfor Operation and Maintenance Management System 3.0.6
Sangfor Operation and Maintenance Management System 3.0.7
Sangfor Operation and Maintenance Management System 3.0.8
Sangfor Operation and Maintenance Management System 3.0.1
Sangfor Operation and Maintenance Management System 3.0.2
Sangfor Operation and Maintenance Management System 3.0.3
Sangfor Operation and Maintenance Management System 3.0.4
Sangfor Operation and Maintenance Management System 3.0.5
Sangfor Operation and Maintenance Management System 3.0.6
Sangfor Operation and Maintenance Management System 3.0.7
Sangfor Operation and Maintenance Management System 3.0.8
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Sangfor
Product
Operation and Maintenance Management System
Version
3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8