CVE-2026-1413

A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
References
Link Resource
https://github.com/LX-LX88/cve/issues/23 Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.342802 Permissions Required VDB Entry
https://vuldb.com/?id.342802 Third Party Advisory VDB Entry
https://vuldb.com/?submit.736522 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:sangfor:operation_and_maintenance_security_management_system:*:*:*:*:*:*:*:*

History

29 Apr 2026, 01:00

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en el Sistema de Gestión de Seguridad de Operación y Mantenimiento de Sangfor hasta la versión 3.0.12. Esto afecta la función portValidate del archivo /fort/ip_and_port/port_validate del componente Manejador de Solicitudes POST HTTP. Realizar una manipulación del argumento port resulta en inyección de comandos. El ataque puede iniciarse de forma remota. El exploit se ha hecho público y podría ser utilizado.

30 Jan 2026, 16:47

Type Values Removed Values Added
First Time Sangfor
Sangfor operation And Maintenance Security Management System
CPE cpe:2.3:a:sangfor:operation_and_maintenance_security_management_system:*:*:*:*:*:*:*:*
References () https://github.com/LX-LX88/cve/issues/23 - () https://github.com/LX-LX88/cve/issues/23 - Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.342802 - () https://vuldb.com/?ctiid.342802 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.342802 - () https://vuldb.com/?id.342802 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.736522 - () https://vuldb.com/?submit.736522 - Third Party Advisory, VDB Entry

26 Jan 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 02:15

Updated : 2026-04-29 01:00


NVD link : CVE-2026-1413

Mitre link : CVE-2026-1413

CVE.ORG link : CVE-2026-1413


JSON object : View

Products Affected

sangfor

  • operation_and_maintenance_security_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')