Description
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-01-22
Score: 8.7 High
EPSS: 6.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to version 3.0.12. The affected component is the SessionController function within the SSH Protocol Handler. By manipulating the keypassword argument, an attacker can inject arbitrary operating‑system commands that are executed with the privileges of the running service. The flaw allows remote execution, and a publicly available proof‑of‑concept exploit can be used.

Affected Systems

All instances of Sangfor Operation and Maintenance Management System version 3.0.12 or earlier are vulnerable. The impacted component is the SSH Protocol Handler located in the /isomp-protocol/protocol/session file. Organizations using this product must verify whether they are running a vulnerable release and take remediation measures accordingly.

Risk and Exploitability

The CVSS score of 8.7 reflects high severity, with the exploit being achievable remotely. EPSS indicates a 6% likelihood of exploitation, and the vulnerability is not yet in the CISA KEV catalog. The publicly available proof‑of‑concept demonstrates that the attack can be launched over the network by manipulating the keypassword argument, although the CVE does not specify whether authentication is required.

Generated by OpenCVE AI on June 18, 2026 at 11:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or upgrade to a fixed version if released.
  • Restrict access to the SSH Protocol Handler by configuring firewall rules or limiting trusted IP ranges when a patch is not immediately available.
  • Configure input validation or disable the keypassword capability in configuration to mitigate command injection until a permanent fix is deployed.

Generated by OpenCVE AI on June 18, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 30 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:sangfor:operation_and_maintenance_security_management_system:*:*:*:*:*:*:*:*

Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Sangfor
Sangfor operation And Maintenance Security Management System
Vendors & Products Sangfor
Sangfor operation And Maintenance Security Management System

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 22 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sangfor Operation And Maintenance Security Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:52:16.272Z

Reserved: 2026-01-22T07:40:46.347Z

Link: CVE-2026-1324

cve-icon Vulnrichment

Updated: 2026-01-22T20:21:40.907Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-22T15:16:50.420

Modified: 2026-06-17T10:15:36.013

Link: CVE-2026-1324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T11:30:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')