{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/operation-and-maintenance-security-management-system-3.0.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-18641"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Operation and Maintenance Security Management System (3.0.13)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-18641","remote-code-execution","command-injection","sangfor"],"_cs_type":"advisory","_cs_vendors":["Sangfor"],"content_html":"\u003cp\u003eThe Sangfor Operation and Maintenance Security Management System, specifically versions up to 3.0.13, is vulnerable to an OS command injection flaw within the 'com.sbr.fort.foreignDP.DpLoginController' function. The vulnerability is triggered via the '/fort/portal_login' endpoint, which fails to properly sanitize user input, allowing an unauthenticated remote attacker to execute arbitrary OS commands on the underlying appliance. Given the public disclosure of the exploit and the lack of vendor response, this vulnerability poses a significant risk to the security of these management systems. Organizations utilizing this platform should assume that the vulnerability is exploitable and implement perimeter controls to restrict access to the affected endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for complete system compromise, enabling attackers to execute arbitrary commands with the privileges of the web service. This can lead to the exfiltration of sensitive configuration data, credentials, and full administrative control over the appliance. As this system is used for infrastructure management, impact includes potential lateral movement into protected network segments and permanent loss of confidentiality, integrity, and availability of the managed environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for requests to '/fort/portal_login' containing unusual characters (e.g., shell operators like ';', '|', '\u0026amp;\u0026amp;', or '`').\u003c/li\u003e\n\u003cli\u003eRestrict network access to the management interface to authorized administrative IP ranges only.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the appliance to prevent communication with known malicious C2 infrastructure if compromised.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized account modifications or the spawning of shell processes from the web application service user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T20:48:35Z","date_published":"2026-08-03T20:48:35Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sangfor-cve-2026-18641/","summary":"An unauthenticated remote OS command injection vulnerability in the Sangfor Operation and Maintenance Security Management System allows attackers to execute arbitrary system commands via the /fort/portal_login endpoint.","title":"Remote Command Injection in Sangfor Operation and Maintenance Security Management System","url":"https://feed.craftedsignal.io/briefs/2026-08-sangfor-cve-2026-18641/"}],"language":"en","title":"CraftedSignal Threat Feed - Operation and Maintenance Security Management System (3.0.13)","version":"https://jsonfeed.org/version/1.1"}