References https://github.com/izj007/wechat/blob/main/articles/%5B%E6%8E%8C%E6%8E%A7%E5%AE%89%E5%85%A8EDU%5D-2023-8-9-Nacos-Sync-%E6%9C%AA%E6%8E%88%E6%9D%83%E8%BF%9B%E5%90%8E%E5%8F%B0%EF%BC%88%E5%BB%BA%E8%AE%AE%E8%87%AA%E6%9F%A5%EF%BC%89.md http://www.xcxan.cn/archives/245 https://www.ddpoc.com/DVB-2024-5889.html https://avd.aliyun.com/detail/AVD-2024-1719105 https://fr.scribd.com/document/794659219/%E5%85%B3%E4%BA%8ENacos-Sync%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E%E7%9A%84%E9%A2%84%E8%AD%A6%E9%80%9A%E7%9F%A5
Related VulnerabilitiesPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCnacos-v3-auth-scope-bypass: Nacos 3.x - Unauthenticated Admin TakeoverPoCjohnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default LoginFlowise /api/v1/loginmethod 未授权访问漏洞(CVE-2026-56270)PoClitellm-default-login: LiteLLM - Default LoginPoCntopng-auth-bypass: Ntopng Authentication BypassPoCtp-link-wr840n-auth-bypass: TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper AuthenticationPoCnet-vision-default-login: Net Vision UPS Monitor - Default LoginPoC3xui-default-login: 3X-UI - Default LoginPoC泛微E-cology10 /papi/passport/appnew/login/appLogin 未授权访问漏洞WordPress /wp-login.php 跨站脚本攻击漏洞(CVE-2026-64638)ZKTeco BioTime 平台 /accounts/login 默认口令漏洞PoCsentinel-default-login: Alibaba Sentinel - Default Login