cve-2025-34041
CRITICAL CVSS 10.0 opencve
Description
An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.
Timeline
- Published
- 2025-06-24 02:15 UTC
- Last Modified
- 2026-06-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 4.0 | 10.0 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
mitre | ||
| 4.0 | 10.0 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
nvd | ||
| 4.0 | 10.0 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"advisories": [
{
"id": "EUVD-2025-18973",
"source": "euvd",
"title": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds.",
"url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18973"
}
],
"cve": "CVE-2025-34041",
"epss": {
"score": 0.07
},
"mitre": {
"cpes": [
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.16:*:*:*:*:*:*:*",
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.17:*:*:*:*:*:*:*",
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.19:*:*:*:*:*:*:*"
],
"created": "2025-06-24T01:39:59.289000+00:00",
"description": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {
"score": 10,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
},
"mitre_repo_path": "cves/2025/34xxx/CVE-2025-34041.json",
"references": [
"https://vulncheck.com/advisories/sangfor-edr-command-injection",
"https://www.cnvd.org.cn/flaw/show/CNVD-2020-46552",
"https://www.sangfor.com/blog/cybersecurity/sangfor-endpoint-secure-remote-command-execution-vulnerability"
],
"title": "Sangfor Endpoint Detection and Response OS Command Injection",
"updated": "2026-07-14T22:25:39.973000+00:00",
"vendors": [
"symantec",
"symantec$PRODUCT$endpoint_detection_and_response"
],
"weaknesses": [
"CWE-78"
]
},
"nvd": {
"cpes": [],
"created": "2025-06-24T02:15:22.820000+00:00",
"description": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {
"score": 10.0,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"nvd_repo_path": "2025/CVE-2025-34041.json",
"references": [
"https://vulncheck.com/advisories/sangfor-edr-command-injection",
"https://www.cnvd.org.cn/flaw/show/CNVD-2020-46552",
"https://www.sangfor.com/blog/cybersecurity/sangfor-endpoint-secure-remote-command-execution-vulnerability"
],
"title": null,
"updated": "2026-06-17T09:13:21.777000+00:00",
"vendors": [],
"weaknesses": [
"CWE-78"
]
},
"opencve": {
"changes": [
{
"created": "2025-06-24T01:45:00+00:00",
"data": [
{
"details": {
"new": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds.",
"old": null
},
"type": "description"
},
{
"details": {
"new": "Sangfor Endpoint Detection and Response OS Command Injection",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-78"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"https://vulncheck.com/advisories/sangfor-edr-command-injection",
"https://www.cnvd.org.cn/flaw/show/CNVD-2020-46552",
"https://www.sangfor.com/blog/cybersecurity/sangfor-endpoint-secure-remote-command-execution-vulnerability"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV4_0": {
"score": 10,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "f8c1ea33-ba65-4745-85de-104dcf2e8299"
},
{
"created": "2025-06-24T16:15:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "c91b09cb-265f-442f-b53e-b7eb6ba96c9e"
},
{
"created": "2025-11-17T21:45:00+00:00",
"data": [
{
"details": {
"new": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-07-05 UTC.",
"old": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds."
},
"type": "description"
}
],
"id": "8a9c1545-b25b-42b0-84b5-0ac2320f52b4"
},
{
"created": "2025-11-20T21:15:00+00:00",
"data": [
{
"details": {
"new": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
"old": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-07-05 UTC."
},
"type": "description"
}
],
"id": "c87f3a06-ea4b-40a1-a6b2-3ff3b97d9539"
},
{
"created": "2026-07-14T22:45:00+00:00",
"data": [
{
"details": [
"symantec",
"symantec$PRODUCT$endpoint_detection_and_response"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.16:*:*:*:*:*:*:*",
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.17:*:*:*:*:*:*:*",
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.19:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"symantec",
"symantec$PRODUCT$endpoint_detection_and_response"
],
"removed": []
},
"type": "vendors"
}
],
"id": "8fb55527-d4e0-4e07-980e-a1953c9ee5c8"
}
],
"cpes": {
"data": [
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.16:*:*:*:*:*:*:*",
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.17:*:*:*:*:*:*:*",
"cpe:2.3:a:symantec:endpoint_detection_and_response:3.2.19:*:*:*:*:*:*:*"
],
"providers": [
"mitre"
]
},
"created": {
"data": "2025-06-24T01:39:59.289000+00:00",
"provider": "mitre"
},
"description": {
"data": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {},
"provider": null
},
"cvssV4_0": {
"data": {
"score": 10,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
},
"provider": "mitre"
},
"epss": {
"data": {
"score": 0.07
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://vulncheck.com/advisories/sangfor-edr-command-injection",
"https://www.cnvd.org.cn/flaw/show/CNVD-2020-46552",
"https://www.sangfor.com/blog/cybersecurity/sangfor-endpoint-secure-remote-command-execution-vulnerability"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Sangfor Endpoint Detection and Response OS Command Injection",
"provider": "mitre"
},
"updated": {
"data": "2026-07-14T22:25:39.973000+00:00",
"provider": "mitre"
},
"vendors": {
"data": [
"symantec",
"symantec$PRODUCT$endpoint_detection_and_response"
],
"providers": [
"mitre"
]
},
"weaknesses": {
"data": [
"CWE-78"
],
"providers": [
"mitre",
"nvd"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2025-06-24T01:39:59.289000+00:00",
"description": "An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": "Sangfor Endpoint Detection and Response OS Command Injection",
"updated": "2025-06-24T15:37:19.725000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2025/34xxx/CVE-2025-34041.json",
"weaknesses": []
}
}
Enrichment data
Aggregated bundle (all enrichments)