CVE-2023-30804: Sangfor Next-Gen Application Firewall

Medium severity, CVSS 6.5. EPSS: 34% chance of exploitation in the next 30 days.

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.

Affected products

  • Sangfor Next-Gen Application Firewall: version 8.0.17 only

Published 2023-10-10. Last modified 2026-10-01.