Home

Description

Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.

PUBLISHED Reserved 2025-06-22 | Published 2025-06-22 | Updated 2025-06-23 | Assigner mitre




MEDIUM: 4.3CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Problem types

CWE-732 Incorrect Permission Assignment for Critical Resource

Product status

Default status
unknown

2.4.10
affected

References

github.com/r00t7oo2jm/cVetest/blob/main/p0c.sh

github.com/r00t7oo2jm/cVetest/blob/main/sangf0r-poc.pdf

marketplace.huaweicloud.com/...f-57b5-4780-9c0c-58af8f7f71e6

community.sangfor.com/forum.php?mod=viewthread&tid=10842

cve.org (CVE-2025-52923)

nvd.nist.gov (CVE-2025-52923)

Download JSON