CVE 5.3 MEDIUM

Sangfor Operation and Maintenance Security Management System HTTP POST Request port_validate portValidate command injection_CVE-2026-1413

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

Basic Information

ID CVE-2026-1413
Source VulDB
Published Jan 26, 2026 at 01:32

Affected Product

Vendor Sangfor
Product Operation and Maintenance Security Management System
Version 3.0.0
Affected Versions Sangfor Operation and Maintenance Security Management System 3.0.0
Sangfor Operation and Maintenance Security Management System 3.0.1
Sangfor Operation and Maintenance Security Management System 3.0.2
Sangfor Operation and Maintenance Security Management System 3.0.3
Sangfor Operation and Maintenance Security Management System 3.0.4
Sangfor Operation and Maintenance Security Management System 3.0.5
Sangfor Operation and Maintenance Security Management System 3.0.6
Sangfor Operation and Maintenance Security Management System 3.0.7
Sangfor Operation and Maintenance Security Management System 3.0.8
Sangfor Operation and Maintenance Security Management System 3.0.9
Sangfor Operation and Maintenance Security Management System 3.0.10
Sangfor Operation and Maintenance Security Management System 3.0.11
Sangfor Operation and Maintenance Security Management System 3.0.12

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.