References https://www.twcert.org.tw/tw/cp-132-10624-6599c-1.html https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/7ed4f02a-7f05-416f-9021-d5cf3063c827/ https://www.appsecure.security/vulnerability-database/cve-2026-0854/ https://www.meritlilin.com/security/securityPDFs/M00176%20VULNERABILITY%20CameraCh.pdf https://www.twcert.org.tw/en/cp-139-10623-4f523-2.html https://lic.nuk.edu.tw/p/406-1012-94665,r73.php?Lang=zh-tw https://libinfo.fgu.edu.tw/zh_tw/news/-%E6%BC%8F%E6%B4%9E%E9%A0%90%E8%AD%A6-%E5%88%A9%E5%87%8C%EF%BD%9C%E7%9B%A3%E6%8E%A7%E4%B8%BB%E6%A9%9F-OS-Command-Injection-CVE-2026-0854-61671660
Related VulnerabilitiesPoCCVE-2025-51683: mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-21875: ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL InjectionPoCCVE-2026-56292: AcyMailing < 10.11.1 - Unauthenticated SQL InjectionPoCCVE-2026-59509: cve-search 4.0-6.0.0 - Unauthenticated NoSQL InjectionPoCCVE-2026-9586: Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection思考軟體科技|電子柵欄 - SQL Injection綠色運算|NUMail - OS Command InjectionPoCCVE-2026-65761: Joomla Easy Store - SQL InjectionPoCCVE-2023-25826: OpenTSDB <= 2.4.1 - Unauthenticated RCE via Gnuplot InjectionPoCCVE-2020-10221: rConfig <= 3.9.4 - Authenticated OS Command InjectionPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL Injection