References https://mrxn.net/jswz/bigant-loginByToken-authbypass.html https://www.gm7.org/archives/40992 https://zone.ci/secarticles/wx/496458.html https://www.gm7.org/archives/41942 https://www.ddpoc.com/DVB-2026-10820.html https://security.zone.ci/secarticles/wx/498065.html https://www.gm7.org/archives/41769 https://mrxn.net/record/202602
Related Vulnerabilities即时通讯系统存在信息泄露漏洞杭州九麒科技 BigAnt-Admin系统存在文件上传漏洞杭州九麒科技-BigAnt即时通讯系统 /api/dispersedOrg/upload_file 文件上传漏洞大蚂蚁 (BigAnt) 即时通讯系统 PublicController 任意文件读取漏洞即时通讯系统存在弱口令漏洞PoC杭州九麒科技-BigAnt即时通讯系统 /home/login/loginByToken 权限绕过漏洞大蚂蚁 (BigAnt) 即时通讯系统权限绕过漏洞大蚂蚁 (BigAnt) 即时通讯系统 upload_file 任意文件上传漏洞PoC九麒科技 BigAnt 即时通讯系统 upload_file 任意文件上传漏洞杭州九麒科技-BigAnt即时通讯系统 /index.php/Api/DispersedAddin/upload_file 文件上传漏洞(CNNVD-2025-42704091)PoCCVE-2022-23347: BigAnt Server v5.6.06 - Local File InclusionPoCCVE-2022-23348: BigAnt Server 5.6.06 - Improper Access ControlPoCbigant-default-login: BigAnt - Default Password