References https://ddpoc.com/DVB-2025-9559.html https://cn-sec.com/archives/4235766.html https://cn-sec.com/archives/4234624.html https://nvd.nist.gov/vuln/detail/CVE-2025-47423 https://github.com/Haluka92/CVE-2025-47423 https://access.redhat.com/security/cve/cve-2025-47423 https://avd.aquasec.com/nvd/2025/cve-2025-47423/ https://github.com/advisories/GHSA-x3wr-p869-7p3g https://devhub.checkmarx.com/cve-details/cve-2025-47423/ https://feedly.com/cve/CVE-2025-47423
Related VulnerabilitiesPoCCVE-2026-44343: WGDashboard < 4.3.2 - Unauthenticated File ReadPoCCVE-2026-59177: ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard AccessPoCCVE-2026-15733: WGDashboard <= 4.3.2 - Authenticated OS Command Injection /etc/passwd ReadPoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path TraversalPoCtrino-unauth-cluster: Trino Cluster Overview - Unauthenticated Dashboard ExposureKubernetes Dashboard /api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs 权限绕过漏洞(CVE-2018-18264)Nezha Dashboard /dashboard../data/config.yaml 目录遍历漏洞(CVE-2026-53519)PoClaravel-pulse-unauth: Laravel Pulse - Unauthenticated Dashboard AccessPoCpuppetdb-dashboard-unauth: PuppetDB Dashboard - Unauthenticated AccessKubeflow Dashboard /api/workgroup/env-info 未授权访问漏洞PoCapache-skywalking-dashboard: Apache SkyWalking - DashboardPoCCVE-2025-54597: Heimdall Application Dashboard < 2.7.3 - Reflected XSSPoCargo-workflows-unauth: Argo Workflows - Unauthenticated Dashboard