ID

VAR-202507-3436


TITLE

Qi'anxin Technology Group Co., Ltd.'s SecFox operation and maintenance security management and audit system has a command execution vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-16451

DESCRIPTION

SecFox operation and maintenance security management and audit system is an operation and maintenance security management solution that integrates identity authentication, account management, permission control, and operation and maintenance audit. It provides unified operation and maintenance identity authentication, fine-grained permission control, real-time supervision, and post-event tracing functions to help enterprises build a security management system for pre-event prevention, in-event monitoring, and post-event audit. There is a command execution vulnerability in the SecFox operation and maintenance security management and audit system of Qi'anxin Technology Group Co., Ltd., which can be exploited by attackers to execute commands.

Trust: 0.6

sources: CNVD: CNVD-2025-16451

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-16451

AFFECTED PRODUCTS

vendor:qi anxin groupmodel:secfox operation and maintenance security management and audit systemscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-16451

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2025-16451
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-16451
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2025-16451

EXTERNAL IDS

db:CNVDid:CNVD-2025-16451

Trust: 0.6

sources: CNVD: CNVD-2025-16451

SOURCES

db:CNVDid:CNVD-2025-16451

LAST UPDATE DATE

2025-08-17T23:23:14.866000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-16451date:2025-07-21T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-16451date:2025-07-20T00:00:00