PT-2026-4717 · Sangfor · Sangfor Operation/Maintenance Management System

Hhsw34

·

Published

2026-01-12

·

Updated

2026-01-26

·

CVE-2026-1414

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sangfor Operation and Maintenance Security Management System versions up to 3.0.12
Description A flaw exists in the Sangfor Operation and Maintenance Security Management System that could allow for remote command injection. The issue is located within the HTTP POST Request Handler component, specifically in the getInformation function of the file '/equipment/get Information'. Manipulation of the fortEquipmentIp argument can lead to unauthorized command execution. The exploit has been publicly disclosed.
Recommendations Versions prior to 3.0.12 should be updated.

Exploit

Fix

Command Injection

OS Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00993
CVE-2026-1414

Affected Products

Sangfor Operation/Maintenance Management System