CVE-2025-15500

CRITICAL

Sangfor Operation and Maintenance Management System <= 3.0.8 - OS Command Injection via sessionPath Parameter

Title source: llm
STIX 2.1

Description

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.340345
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.340345
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.727208
Exploit, Issue Tracking, Third Party Advisory issue-tracking
https://github.com/master-abc/cve/issues/11
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/master-abc/cve/issues/11#issue-3770602189

Scores

CVSS v3 9.8
EPSS 0.0559
EPSS Percentile 91.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
sangfor/operation_and_maintenance_management_system < 3.0.8
Published Jan 09, 2026
Tracked Since Feb 18, 2026