漏洞描述 Apache APISIX 是一个动态、实时、高性能的开源 API网关,提供负载均衡、动态上游、灰度发布、服务熔断、身份认证、可观测性等丰富的流量管理功能,该系统命令执行漏洞,攻击者可以直接获取服务器权限。
相关漏洞推荐 Apache Airflow Providers Edge3 设计缺陷漏洞 POC unauth-munin: Munin Monitoring Dashboard - Exposure Apache Struts2 资源释放不当漏洞 POC CVE-2018-17082: Apache2 - Transfer-Encoding Chunked XSS POC apache-hive-config: Apache Hive Configuration - Exposure POC unauth-akhq-dashboard: AKHQ Dashboard - Unauthenticated Access POC unauth-hawkeye-dashboard: Unauth Hawkeye Dashboard - Detect POC unauth-phoenix-dashboard: Unauth Phoenix Dashboard - Detect POC unauth-supervisor-dashboard: Unauth Supervisor Dashboard - Detect (CVE-2025-11461)Frappe CRM 1.53.1 Dashboard Controller SQL注入漏洞 Apache Tomcat URL重写绕过漏洞 (CVE-2025-55752) Apache Tomcat 存在路径遍历漏洞(CVE-2025-55752) Apache ActiveMQ NMS AMQP Client 反序列化漏洞