References https://www.twcert.org.tw/tw/cp-132-10864-944b1-1.html https://www.twcert.org.tw/newepaper/cp-151-10864-944b1-3.html https://nvd.nist.gov/vuln/detail/CVE-2026-6947 https://stack.watch/vuln/CVE-2026-6947/ https://github.com/advisories/GHSA-j7j4-xj8f-m78g https://mondoo.com/vulnerability-intelligence/vulnerability/CVE-2026-6947 https://www.tenable.com/cve/CVE-2026-6947 https://www.dlink.com/tw/zh/products/dwm-222w-4g-lte-ax300-wifi-6-usb-adapter https://vuldb.com/cve/CVE-2026-6947 https://www.sentinelone.com/vulnerability-database/cve-2026-6947/
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-48558: SimpleHelp <=5.5.15 - OIDC JWT Authentication BypassPoCCVE-2026-53595: FreeScout < 1.8.224 - Invite Hash Authorization BypassPoCCVE-2026-60105: Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist BypassPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass