SecAlerts
sangfor logo

sangfor

Security Risk Profile

71
/100
high

Security Risk Score

Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 26, 2022 to present

22
Total CVEs
17
Critical+High
0
Exploited
17
Unpatched

Threat Assessment

Avg CVSS
8.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
17
Critical/High
Risk Level
71/100
high
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
15
High
2
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
13
2
OS Command Injection
9
3
Malicious File Upload
1
4
XEE
1
5
SSRF
1

Most Affected Products

1. Sangfor Operation and Maintenance Security Management System16
2. Sangfor Operation and Maintenance Management System8
3. Sangfor Next-Gen Application Firewall5
4. Sangfor Atrust2
5. Sangfor Behavior Management System1

Recent Vulnerabilities

See more →
CVE-2026-18641
CVSS 5.5medium

Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection

8/3/2026🔧 No Patch
CVE-2026-1414
CVSS 9.8critical

Sangfor Operation and Maintenance Security Management System HTTP POST Request get_Information getInformation command injection

1/26/2026🔧 No Patch
CVE-2026-1413
CVSS 9.8critical

Sangfor Operation and Maintenance Security Management System HTTP POST Request port_validate portValidate command injection

1/26/2026🔧 No Patch
CVE-2026-1412
CVSS 9.8critical

Sangfor Operation and Maintenance Security Management System HTTP POST Request get_clip_img command injection

1/26/2026🔧 No Patch
CVE-2026-1325
CVSS 9.8EPSS 0%critical

Sangfor Operation and Maintenance Security Management System edit_pwd_mall password recovery

1/22/2026🔧 No Patch
CVE-2026-1324
CVSS 9.8EPSS 0%critical

Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection

1/22/2026🔧 No Patch
CVE-2025-15503
CVSS 9.8critical

Sangfor Operation and Maintenance Management System common.jsp unrestricted upload

1/10/2026🔧 No Patch
CVE-2025-15502
CVSS 9.8critical

Sangfor Operation and Maintenance Management System session SessionController os command injection

1/10/2026🔧 No Patch
CVE-2025-15501
CVSS 10.0critical

Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection

1/9/2026🔧 No Patch
CVE-2025-15500
CVSS 10.0critical

Sangfor Operation and Maintenance Management System HTTP POST Request getHis os command injection

1/9/2026🔧 No Patch

Monitor sangfor in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.