CVE-2025-15501: Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15501?
CVE-2025-15501 is classified as a critical severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2025-15501?
To fix CVE-2025-15501, update the Sangfor Operation and Maintenance Management System to version 3.0.9 or later.
What kind of exploitation is possible with CVE-2025-15501?
CVE-2025-15501 allows for remote exploitation leading to OS command injection through the manipulated sessionPath argument.
Which versions of Sangfor Operation and Maintenance Management System are affected by CVE-2025-15501?
Sangfor Operation and Maintenance Management System versions up to and including 3.0.8 are affected by CVE-2025-15501.
What is the function affected in CVE-2025-15501?
The function affected in CVE-2025-15501 is WriterHandle.getCmd located in the file /isomp-protocol/protocol/getCmd.