Showing 1 vulnerability on this page for Endpoint Detection and Response Platform

Signals CISA KEV Ransomware Nuclei
Sangfor Technologies Co., Ltd. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Sangfor Endpoint Detection and Response OS Command Injection

An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-

CWE-78Jun 24, 2025
CVSS10.0v4.0EPSS6.97%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX