---
id: CVE-2023-30804
title: >-
  The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to
  an authenticated file disclosure vulnerability
summary: >-
  The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to
  an authenticated file disclosure vulnerability. A remote and authenticated
  attacker can read arbitrary system files using the svpn_html/loadfile.php
  endpoint. …
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: sangfor
product: next-gen_application_firewall
affected:
  - next-gen_application_firewall = 8.0.17
published: '2023-10-10'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:17.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-30804'
references:
  - url: >-
      https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/sangfor/sangfor-ngaf-lfi.yaml
    label: disclosure@vulncheck.com
  - url: >-
      https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/
    label: disclosure@vulncheck.com
  - url: 'https://vulncheck.com/advisories/sangfor-ngaf-auth-file-disclosure'
    label: disclosure@vulncheck.com
  - url: 'https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vulncheck.com/advisories/sangfor-ngaf-auth-file-disclosure'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-09-19T14:22:02.639064Z'
epss: 0.12816
epssPercentile: 0.96175
ingestedAt: '2026-10-01T15:48:17.792Z'
---

## Overview

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.

## Affected

- `next-gen_application_firewall = 8.0.17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
