References https://nvd.nist.gov/vuln/detail/CVE-2022-26672 https://www.twcert.org.tw/tw/cp-132-6041-7bd67-1.html https://nvd.nist.gov/vuln/detail/cve-2022-26672 https://exchange.xforce.ibmcloud.com/vulnerabilities/225047 https://db.gcve.eu/vuln/cve-2022-26672 https://cve.imfht.com/product/WebStorage?lang=en https://www.zdnet.com/article/asus-webstorage-abused-to-spy-on-users-at-the-router-level/ https://gist.github.com/roycewilliams/cf7fce5777d47a8b22265515dba8d004 https://mrbruh.com/asus_p2/ https://www.welivesecurity.com/2019/05/14/plead-malware-mitm-asus-webstorage/
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposurePoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCpypirc-credentials-exposure: Python .pypirc Credentials - ExposurePoCCVE-2026-18963: Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials BypassPoCCVE-2026-56265: Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication BypassPoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials盛源|DMS+ (非行動端) - Use of Hard-coded Credentials博格資訊管理顧問|ERP App - Use of Hard-coded CredentialsPoCCVE-2020-10532: WatchGuard Fireware AD Helper Component - Credentials DisclosurePoCfrappe-default-login: Frappe Framework - Default Login Credentials