CVE 5.3 MEDIUM

Sangfor Operation and Maintenance Security Management System HTTP POST Request get_Information getInformation command injection_CVE-2026-1414

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation of the file /equipment/get_Information of the component HTTP POST Request Handler. Executing a manipulation of the argument fortEquipmentIp can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Basic Information

ID CVE-2026-1414
Source VulDB
Published Jan 26, 2026 at 02:02

Affected Product

Vendor Sangfor
Product Operation and Maintenance Security Management System
Version 3.0.0
Affected Versions Sangfor Operation and Maintenance Security Management System 3.0.0
Sangfor Operation and Maintenance Security Management System 3.0.1
Sangfor Operation and Maintenance Security Management System 3.0.2
Sangfor Operation and Maintenance Security Management System 3.0.3
Sangfor Operation and Maintenance Security Management System 3.0.4
Sangfor Operation and Maintenance Security Management System 3.0.5
Sangfor Operation and Maintenance Security Management System 3.0.6
Sangfor Operation and Maintenance Security Management System 3.0.7
Sangfor Operation and Maintenance Security Management System 3.0.8
Sangfor Operation and Maintenance Security Management System 3.0.9
Sangfor Operation and Maintenance Security Management System 3.0.10
Sangfor Operation and Maintenance Security Management System 3.0.11
Sangfor Operation and Maintenance Security Management System 3.0.12

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.