The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.
- https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4
No PoCs found on GitHub currently.