S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Feb 12, 2026

CVE-2025-15503 Scanner

CVE-2025-15503 Scanner - Arbitrary File Upload vulnerability in Sangfor OSM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-15503
5.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Operation and Maintenance Management Systemby Sangfor
3.0.0
Updated Aug 5, 2026View on NVD →
Detail

Sangfor OSM is widely used in enterprises for operational security management. It's designed to simplify the management of IT systems and networks in various sectors by providing centralized control. The software streamlines processes such as monitoring, alerting, and reporting, making it easier for IT departments to maintain secure operations. Typically, Sangfor OSM is deployed within organizations that require stringent oversight of their digital environments. It is popular for its efficiency in managing complex systems, ensuring operational effectiveness and security compliance. Users benefit from its comprehensive suite of tools for managing network security and infrastructure.

The vulnerability in question involves an Arbitrary File Upload flaw within Sangfor OSM. This security issue allows unauthorized attackers to upload arbitrary files to the system, incrementing the risk of remote code execution. Exploitation does not require any special authentication, making it particularly dangerous. This vulnerability, identified in version 3.0.8 and lower, could be utilized to perform harmful operations on the target system. If not addressed, this flaw might lead to severe security breaches, compromising sensitive data and system integrity. The vulnerability arises due to inadequate input validation processes for file uploads.

Technical details of this vulnerability include the manipulation of the "File" argument in the endpoint /fort/trust/version/common/common.jsp. Attackers can craft malicious upload requests using the Content-Type "multipart/form-data" to inject harmful payloads. Successful exploitation requires sending a specially designed POST request to the vulnerable endpoint with the payload containing malicious code within a JSP file. Once uploaded, these files can be executed on the server, potentially causing system compromise. The template detects this by verifying response status codes and body contents to ensure the success of the upload.

If exploited, this vulnerability could lead to catastrophic effects on the affected systems. Malicious actors may execute arbitrary code, potentially gaining full control over the targeted system. This control allows for data breaches, unauthorized access to sensitive information, and the ability to disrupt or hinder business operations. Additionally, compromised systems may be leveraged to conduct further attacks or spread malware within the network. The impact on organizations can include financial loss, reputational damage, and legal liabilities.

REFERENCES

Solution Advice
  • Update Sangfor OSM to the latest version available to patch the vulnerability.
  • Implement additional validation checks on file uploads to restrict executable file types.
  • Regularly audit and monitor the system for unauthorized activities to quickly identify potential breaches.
  • Enhance security measures by adjusting firewall settings and intrusion detection systems.
  • Provide regular security training and awareness sessions for the IT staff to prevent future incidents.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.