References https://www.twcert.org.tw/tw/cp-132-7505-a0c94-1.html https://www.cvedetails.com/cve/CVE-2023-41354/ https://github.com/advisories/GHSA-5297-2xjq-2cfx https://www.twcert.org.tw/newepaper/cp-151-7505-a0c94-3.html https://nvd.nist.gov/vuln/detail/CVE-2023-41355 https://cve.imfht.com/detail/CVE-2023-41355?lang=en https://www.cvedetails.com/cve/CVE-2023-41355/ https://github.com/advisories/GHSA-w6x6-2wp3-jqvp
Related VulnerabilitiesPoCtp-link-wr840n-auth-bypass: TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper AuthenticationPoCCVE-2026-4987: SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via form_id技嘉科技|Gigabyte Control Center - Improper Access ControlPoCCVE-2026-32230: Uptime-Kuma < v1.23.0 - Improper Access ControlPoCCVE-2026-48710: Starlette - Improper Validation of Unsafe Equivalence in Input基點資訊|CelloOS - Improper Access ControlPoCCVE-2021-22017: vCenter Server - Improper Access ControlPoCollama-improper-authorization: Ollama - Improper AuthorizationPoCCVE-2021-20617: Acmailer - Improper Access Control to OS Command InjectionPoCCVE-2025-12480: Triofox - Improper Access ControlPoCCVE-2020-13935: Apache Tomcat WebSocket Frame Payload Length Validation Denial of ServicePoCCVE-2018-16668: CirCarLife <4.3 - Improper AuthenticationPoCCVE-2018-16670: CirCarLife <4.3 - Improper Authentication