References https://www.twcert.org.tw/tw/cp-132-7083-94e13-1.html https://nvd.nist.gov/vuln/detail/CVE-2022-47617 https://tp2rc.tanet.edu.tw/node/678 https://www.twcert.org.tw/en/cp-139-7088-ae1ba-2.html https://github.com/advisories/ghsa-3529-fghx-8h6c https://cve.imfht.com/detail/CVE-2022-47617 https://dbugs.ptsecurity.com/vulnerability/PT-2023-15438 https://strobes.co/vi/cve/CVE-2022-47617 https://app.opencve.io/cve/?vendor=hitrontech&product=coda-5310
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-56265: Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication BypassPoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials盛源|DMS+ (非行動端) - Use of Hard-coded Credentials博格資訊管理顧問|ERP App - Use of Hard-coded Credentials九佳易管理系统 PrivilegedCodeDestroy SQL注入漏洞PoCCVE-2025-69971: FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication BypassWordPress Drag and Drop Multiple File Upload for WooCommerce dnd_codedropz_upload_wc 文件上传漏洞(CVE-2025-4403)九佳易 Interface/licx/PrivilegedCodeDestroy.asmx/UpdatePrivilegedState SQL 注入漏洞PoCCVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded Credentials