References https://www.twcert.org.tw/tw/cp-132-10091-12462-1.html https://cc.nchu.edu.tw/p/404-1000-1687.php?Lang=zh-tw https://www.tcrc.edu.tw/new/new-list/agentflow-account-lockout-bypass https://forum.flowring.com/post/view?bid=72&id=45611&tpg=1&ppg=1&sty=1&age=30&next=1 https://nvd.nist.gov/vuln/detail/CVE-2025-3709 https://www.ameeba.com/blog/cve-2025-3709-account-lockout-bypass-vulnerability-in-agentflow/ https://www.twcert.org.tw/en/cp-139-10090-112f7-2.html https://net.nthu.edu.tw/netsys/mailing:announcement:20250513_02?do=export_pdf https://www.nchu.edu.tw/news-detail.php?id=59561 https://lis.mcut.edu.tw/p/405-1013-72743,c10249.php?Lang=en
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-19632: TranslatePress <= 3.3.1 - Unauthenticated Account TakeoverPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-48558: SimpleHelp <=5.5.15 - OIDC JWT Authentication BypassPoCCVE-2026-53595: FreeScout < 1.8.224 - Invite Hash Authorization BypassPoCCVE-2026-60105: Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist Bypass