References https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/hikvision/hikvision-js-files-upload.yaml https://s4e.io/tools/hikvision-isecure-center-unrestricted-file-upload https://github.com/fliggyaa/fscanpoc https://cloud.tencent.com/developer/article/2344916 https://www.hikvision.com/en/support/tools/hitools/
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerFileRise /uploads 文件读取漏洞(CVE-2026-25231)鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File UploadPoCCVE-2026-0717: LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings Disclosure網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-0558: LolLMS <= 2.2.0 - Unauthenticated File UploadPoCCVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Arbitrary File UploadPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File Upload二一零零科技|公文管理系統 - Arbitrary File UploadPoCCVE-2024-56064: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCE