CVE-2026-1414: Sangfor Operation and Maintenance Security Management System HTTP POST Request get_Information getInformation command injection
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation of the file /equipment/getInformation of the component HTTP POST Request Handler. Executing a manipulation of the argument fortEquipmentIp can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1414?
CVE-2026-1414 is considered a high severity vulnerability due to its command injection risk.
How do I fix CVE-2026-1414?
To mitigate CVE-2026-1414, upgrade Sangfor Operation and Maintenance Security Management System to version 3.0.13 or later.
What systems are affected by CVE-2026-1414?
CVE-2026-1414 affects Sangfor Operation and Maintenance Security Management System versions up to 3.0.12.
What type of vulnerability is CVE-2026-1414?
CVE-2026-1414 is classified as a command injection vulnerability.
What is the impact of CVE-2026-1414?
The impact of CVE-2026-1414 includes unauthorized command execution which can compromise system integrity.