peter bassill · operator
$ cve CVE-2025-15500 JSON

CVE-2025-15500

9.8
CRITICAL · CVSS 3.1 · EPSS 6.1% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.07% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2026-01-09
Last modified2026-06-17

Affected (1)

VendorProduct
sangforoperation and maintenance management system

References

→ the Explorer  ·  watch your stack  ·  NVD