Back

MEDIUM

Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection

Published Aug 3, 2026

Description

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published Aug 3, 2026
Updated Aug 5, 2026
Reserved Aug 3, 2026

CISA Vulnrichment

Updated Aug 5, 2026

NVD

Status Deferred
Modified Aug 12, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published Aug 3, 2026
Updated Aug 5, 2026

GitHub

No data