References https://www.twcert.org.tw/newepaper/cp-151-7503-a27ed-3.html https://vuldb.com/vuln/244399 https://www.twcert.org.tw/tw/cp-132-7503-a27ed-1.html https://www.cvedetails.com/cve/CVE-2023-41353/ https://www.twcert.org.tw/tw/lp-132-1-18-20.html https://tw.forumosa.com/t/chunghwa-router-nokia-g-040w-q-login/237301
Related VulnerabilitiesPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosuremetaBase reset_password 接口存在sql注入漏洞PoCCVE-2026-44551: Open WebUI 'LDAP Empty Password' - Authentication BypassPoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password RecoveryPoCCVE-2025-62512: Piwigo - User Enumeration via Password ResetBMC FootPrints /footprints/servicedesk/passwordreset/request/ 权限绕过漏洞(CVE-2025-71257/CVE-2025-71258/CVE-2025-71259/CVE-2025-71260)PoCCVE-2025-27506: NocoDB < 0.258.0 - Reflected XSS in Password ResetPoCCVE-2025-56132: LiquidFiles < 4.2 - User Enumeration via Password ResetPoCCVE-2026-23760: SmarterTools SmarterMail - Admin Password ResetPoCSmarterMail /api/v1/auth/force-reset-password 权限绕过漏洞