References https://www.twcert.org.tw/tw/cp-132-10750-3735f-1.html https://www.twcert.org.tw/newepaper/cp-151-10750-3735f-3.html https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-006806.html https://www.twcert.org.tw/newepaper/lp-151-3-2-20.html https://www.twcert.org.tw/tw/lp-132-1-1-60.html https://www.twcert.org.tw/en/cp-139-10751-23871-2.html https://www.sentinelone.com/vulnerability-database/cve-2026-3822/
Related VulnerabilitiesPoCtp-link-wr840n-auth-bypass: TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper AuthenticationPoCCVE-2026-4987: SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via form_id技嘉科技|Gigabyte Control Center - Improper Access ControlPoCCVE-2026-32230: Uptime-Kuma < v1.23.0 - Improper Access ControlPoCCVE-2026-48710: Starlette - Improper Validation of Unsafe Equivalence in InputPoCCVE-2026-50751: Check Point IKEv1 Remote-Access VPN - Certificate Authentication Bypass基點資訊|CelloOS - Improper Access Control深信服运维安全管理系统 /fort/outServices;help/generate_certificate 命令执行漏洞PoCCVE-2021-22017: vCenter Server - Improper Access ControlPoCollama-improper-authorization: Ollama - Improper AuthorizationPoCCVE-2021-20617: Acmailer - Improper Access Control to OS Command Injection金和OA CertificateModify.aspx SQL注入漏洞PoCCVE-2025-12480: Triofox - Improper Access Control