Back to overview

CVE-2025-15501

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2025-15501
State
PUBLISHED
Assigner
VulDB
Reserved
2026-01-09 17:12 UTC
Published
2026-01-09 22:32 UTC
Last updated
2026-02-23 08:27 UTC
Primary CWE
CWE-78
OS Command Injection
Vendor / Product
Sangfor / Operation and Maintenance Management System
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Sangfor Operation and Maintenance Management System 3.0.0, 3.0.1, 3.0.2, 3.0.3 …
Weakness (CWE)
CWESourceDescription
CWE-77 cna Command Injection
CWE-78 cna OS Command Injection
CVSS scores (4)
ScoreSeverityVersionSourceVector
10.0 N/D 2.0 cna AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
9.8 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
References (5)
Back to overview