---
id: CVE-2025-13809
title: >-
  A vulnerability has been found in orionsec orion-ops up to
  5925824997a3109651bbde07460958a7be249ed1
summary: >-
  A vulnerability has been found in orionsec orion-ops up to
  5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some
  unknown functionality of the file
  orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/Ma…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-918
vendor: orionsec
product: orion-ops
affected:
  - orion-ops <= 2025-08-01
published: '2025-12-01'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13809'
references:
  - url: >-
      https://github.com/Xzzz111/exps/blob/main/archives/orion-ops-ssrf-1/report.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/Xzzz111/exps/blob/main/archives/orion-ops-ssrf-1/report.md#proof-of-concept
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.333819'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333819'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.692069'
    label: cna@vuldb.com
  - url: >-
      https://github.com/Xzzz111/exps/blob/main/archives/orion-ops-ssrf-1/report.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/Xzzz111/exps/blob/main/archives/orion-ops-ssrf-1/report.md#proof-of-concept
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00334
epssPercentile: 0.24032
ingestedAt: '2026-09-03T03:55:23.222Z'
---

## Overview

A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some unknown functionality of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineInfoController.java of the component SSH Connection Handler. Such manipulation of the argument host/sshPort/username/password/authType leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. A patch should be applied to remediate this issue. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `orion-ops <= 2025-08-01`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
