CVE-2026-1413: Sangfor Operation and Maintenance Security Management System HTTP POST Request port_validate portValidate command injection
A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ipandport/portvalidate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1413?
CVE-2026-1413 has a high severity rating due to the potential for command injection vulnerabilities.
How do I fix CVE-2026-1413?
To mitigate CVE-2026-1413, update the Sangfor Operation and Maintenance Security Management System to version 3.0.13 or later.
What versions are affected by CVE-2026-1413?
CVE-2026-1413 affects all versions of Sangfor Operation and Maintenance Security Management System up to 3.0.12.
Can CVE-2026-1413 lead to data breaches?
Yes, exploiting CVE-2026-1413 can allow attackers to execute arbitrary commands, potentially leading to data breaches.
Is there a workaround for CVE-2026-1413 if I can't update immediately?
There are no known effective workarounds for CVE-2026-1413, so patching is the recommended course of action.