CVE-2025-15499: Sangfor Operation and Maintenance Management System VersionController.java uploadCN os command injection
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15499?
CVE-2025-15499 is classified as a critical vulnerability due to its potential for os command injection.
How do I fix CVE-2025-15499?
To mitigate CVE-2025-15499, users should upgrade the Sangfor Operation and Maintenance Management System to version 3.0.9 or later.
What type of vulnerability is CVE-2025-15499?
CVE-2025-15499 is an os command injection vulnerability affecting the uploadCN function in the VersionController.java file.
What systems are affected by CVE-2025-15499?
CVE-2025-15499 affects all versions of the Sangfor Operation and Maintenance Management System up to 3.0.8.
Can CVE-2025-15499 be exploited remotely?
Yes, CVE-2025-15499 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected system.