peter bassill · operator
$ cve CVE-2025-15501 JSON

CVE-2025-15501

9.8
CRITICAL · CVSS 3.1 · EPSS 6.9% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.91% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2026-01-09
Last modified2026-06-17

Affected (1)

VendorProduct
sangforoperation and maintenance security management system

References

→ the Explorer  ·  watch your stack  ·  NVD