CVE-2026-1325

Source
https://cve.org/CVERecord?id=CVE-2026-1325
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1325.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1325
Published
2026-01-22T15:16:50.610Z
Modified
2026-03-15T14:15:03.542383Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function editpwdmall of the file /fort/login/editpwdmall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1325.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.0.12"
            }
        ]
    }
]