nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-34041 CVE-2025-34041
CRITICAL
Sangfor Endpoint Detection and Response OS Command Injection
Record summary
CVE-2025-34041 has a selected CVSS score of 10.0 (critical).
Description
An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 23, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 24, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Endpoint Detection and Response (EDR)Browse Sangfor / Endpoint Detection and Response (EDR) | VulnCheck | Version data not supplied | |
Endpoint Detection and Response PlatformBrowse Sangfor Technologies Co., Ltd. / Endpoint Detection and Response PlatformDefault status: unaffected | CVE List | 3.2.16 | affected |
| 3.2.17 | affected | ||
| 3.2.19 | affected | ||
References
4vulncheck.comThird-party advisory
https://vulncheck.com/advisories/sangfor-edr-command-injection cnvd.org.cnThird-party advisory
https://www.cnvd.org.cn/flaw/show/CNVD-2020-46552 sangfor.comVendor advisorypatchTechnical description
https://www.sangfor.com/blog/cybersecurity/sangfor-endpoint-secure-remote-command-execution-vulnerability