216.73.217.22

CVE-2025-34041

· Published 24/06/2025 02:15 · Modified 24/06/2025 02:15

Labels: CVE-2025-34041 2025-06-24CVE-2025-34041CWE-78[email protected]

Essential information

Published
24/06/2025 02:15
Modified
24/06/2025 02:15
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sangfor / endpoint detection and response cpe:2.3:a:sangfor:endpoint_detection_and_response:3.2.16-3.2.19:*:*:*:*:*:*:*

References