Sangfor-CVE-2025-12916
Sangfor CVE-2025-12916 Remote Command Execution Vulnerability Batch Detection Tool || Author: Jinxia Security
A batch detection tool for the CVE-2025-12916 remote command execution vulnerability in Sangfor Operation and Maintenance Security Management System (OSM).
- Vulnerability ID: CVE-2025-12916
- Vulnerability Type: Remote Command Execution
- Affected Versions: Sangfor OSM < 3.0.12 20241106
- Vulnerability File:
/fort/portal_login
- Vulnerability Parameter:
loginUrl
✨ Features
- 🚀 Multi-threaded batch detection
- ⏹️ Ctrl+C graceful stop support
- 📊 Real-time progress display
- 💾 Auto-save results
- 🔍 Multiple payload attempts
- 🛡️ Automatic HTTP/HTTPS switching
- 📈 Detailed statistics report
🛠️ Installation and Usage
Requirements
- Python 3.6+
- Dependencies:
requests