CVE-2026-18641

Summary

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
SangforOperation and Maintenance Security Management System3.0.0affected
SangforOperation and Maintenance Security Management System3.0.1affected
SangforOperation and Maintenance Security Management System3.0.2affected
SangforOperation and Maintenance Security Management System3.0.3affected
SangforOperation and Maintenance Security Management System3.0.4affected
SangforOperation and Maintenance Security Management System3.0.5affected
SangforOperation and Maintenance Security Management System3.0.6affected
SangforOperation and Maintenance Security Management System3.0.7affected
SangforOperation and Maintenance Security Management System3.0.8affected
SangforOperation and Maintenance Security Management System3.0.9affected
SangforOperation and Maintenance Security Management System3.0.10affected
SangforOperation and Maintenance Security Management System3.0.11affected
SangforOperation and Maintenance Security Management System3.0.12affected
SangforOperation and Maintenance Security Management System3.0.13affected

Weaknesses

  • CWE-78: OS Command Injection
  • CWE-77: Command Injection

References