CVE-2025-12916

Source
https://cve.org/CVERecord?id=CVE-2025-12916
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12916.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-12916
Published
2025-11-09T00:15:40.660Z
Modified
2026-03-14T12:41:25.185883Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.0.11 and 3.0.12 is recommended to address this issue. It is advisable to upgrade the affected component.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12916.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "3.0"
            },
            {
                "fixed": "3.0.11"
            }
        ]
    }
]