References https://www.cellopoint.com/notification https://www.twcert.org.tw/tw/cp-132-3845-be6bf-1.html https://www.twcert.org.tw/tw/cp-132-8102-b94a9-1.html https://www.cellopoint.com/post/seg-feedback-2024?lang=zh https://www.thehackerwire.com/critical-oauth-account-hijacking-in-default-installations/ https://www.thehackerwire.com/cellopoint-celloos-ssh-improper-access-control-cve-2026-12059/ https://www.ithome.com.tw/news/165179 https://www.cellopoint.com/post/rce-2024?lang=zh https://www.twcert.org.tw/tw/cp-132-8102-b94a9-1.html
Related VulnerabilitiesPoCCVE-2026-59177: ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard AccessPoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-DirectPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassPoCCVE-2026-86206: N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header SpoofingPoCCVE-2026-86426: LibreNMS <= 26.7.0 - Unauthenticated API AccessPoCjohnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default LoginPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API Access大华-智慧园区综合管理平台 updateAccessChannelByVisit SQL注入漏洞畅捷通T+系统 AccountExtendRuleController接口处存在反序列化漏洞PoCtp-link-wr840n-auth-bypass: TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper Authentication金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞金和OA /c6/JHSoft.Web.CostControl/BudgetExecution/VouchUpdate.aspx SQL 注入漏洞PoCseaweedfs-unauth: SeaweedFS Filer - Unauthenticated Access