Sangfor Technologies Co., Ltd. Vulnerabilities and Affected Products
Vulnerabilities associated with Endpoint Detection and Response Platform.
Products
Clear product- Endpoint Detection and Response Platform1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-34041CRITICAL | Sangfor Endpoint Detection and Response OS Command InjectionAn OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-… CWE-78Jun 24, 2025 | CVSS10.0v4.0 | EPSS6.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |