Record summary

CVE-2025-34041 has a selected CVSS score of 10.0 (critical).

Description

An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 23, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 24, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Endpoint Detection and Response (EDR)

Browse Sangfor / Endpoint Detection and Response (EDR)
VulnCheckVersion data not supplied

Default status: unaffected

CVE List3.2.16affected
3.2.17affected
3.2.19affected

References

4