References https://www.twcert.org.tw/en/cp-139-10115-f5f14-2.html https://www.twcert.org.tw/tw/cp-132-10114-10b4b-1.html https://cc.ncku.edu.tw/var/file/213/1213/img/4803/656751040.pdf https://nvd.nist.gov/vuln/detail/CVE-2025-4558 https://vuldb.com/?id.308309 https://www.nchu.edu.tw/news-detail.php?id=59587 https://isms.ccu.edu.tw/p/404-1044-74223.php?Lang=zh-tw https://lis.mcut.edu.tw/p/406-1013-72881,r11.php?Lang=en
Related VulnerabilitiesPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosuremetaBase reset_password 接口存在sql注入漏洞PoC大华智慧园区综合管理平台 config_changePort SQL注入漏洞用友 U8cloud /service/XChangeServlet SQL 注入漏洞关于U8cloud所有版本XChangeServlet接口存在SQL注入漏洞的安全公告广联达OA /GB/LK/Document/DataExchange/DataExchange.ashx XML 外部实体注入漏洞广联达OA /Org/service/Service.asmx/GetChangeUsers 信息泄露漏洞PoCCVE-2026-25527: changedetection.io <= 0.52.9 - Unauthenticated Path TraversalPoCCVE-2026-44551: Open WebUI 'LDAP Empty Password' - Authentication Bypasschangedetection.io /static/%2e%2e/flask_app.py 目录遍历漏洞(CVE-2026-25527)changedetection.io <= 0.53.9 存在路径遍历漏洞(CVE-2026-25527)