CVE-2025-12916: Sangfor Operation and Maintenance Security Management System Frontend portal_login command injection
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portallogin of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.0.11 and 3.0.12 is recommended to address this issue. It is advisable to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12916?
CVE-2025-12916 has a critical severity rating due to the potential for command injection.
How do I fix CVE-2025-12916?
To fix CVE-2025-12916, upgrade the Sangfor Operation and Maintenance Security Management System to version 3.0.12 or later.
Which versions of Sangfor Operation and Maintenance Security Management System are affected by CVE-2025-12916?
CVE-2025-12916 affects versions of Sangfor Operation and Maintenance Security Management System up to and including version 3.0.11.
What type of vulnerability is CVE-2025-12916?
CVE-2025-12916 is a command injection vulnerability associated with the loginUrl parameter.
Can CVE-2025-12916 be exploited remotely?
Yes, CVE-2025-12916 can be exploited remotely by manipulating the loginUrl argument of the affected system.