Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sangfor

First CVE: Feb 26, 2022Active for: 4 yearsTotal CVEs: 18
65.7
VTI Score
TOP TARGET

Sangfor develops a focused portfolio of enterprise security and infrastructure products, including network firewalls, application delivery systems, and endpoint virtualization solutions, that sit on critical network boundaries and administrative access paths. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through command-injection and authentication-bypass weaknesses that are particularly impactful in appliances and management systems where exploitation can yield system-level compromise. Defenders should treat Sangfor advisories as high-priority, especially for internet-exposed appliances and administrative interfaces; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.9
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sangfor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 26, 2022
4 years ago
Most Recent CVE
Jan 26, 2026
179 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-30806CRITICAL
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute
Oct 10, 20239.864NONO
CVE-2023-30805CRITICAL
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute
Oct 10, 20239.864NONO
CVE-2025-15503CRITICAL
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/
Jan 10, 20269.844NOYES
CVE-2025-15501CRITICAL
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol
Jan 9, 20269.838NONO
CVE-2025-15500CRITICAL
A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis
Jan 9, 20269.838NONO
CVE-2026-1324CRITICAL
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-prot
Jan 22, 20269.837NONO
CVE-2025-15499CRITICAL
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.ja
Jan 9, 20269.835NONO
CVE-2026-1325CRITICAL
A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/ed
Jan 22, 20269.834NONO
CVE-2026-1412CRITICAL
A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown function of the file /fort/audit/get
Jan 26, 20269.833NONO
CVE-2025-15502CRITICAL
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protoco
Jan 10, 20269.833NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
22%
78%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local2 (11.1%)
Network16 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None17 (94.4%)
Unknown0 (0.0%)
Required1 (5.6%)
Privileges Required
Low2 (11.1%)
High1 (5.6%)
None15 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sangfor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sangfor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sangfor's Products

View all 3 CNAs →

Top CWEs