References https://mrxn.net/news/fnos-Directory-Traversal-rce.html https://zhuanlan.zhihu.com/p/2002081598493980521 https://post.smzdm.com/p/a2qdg89d https://post.smzdm.com/p/aogzmlo7 https://dragonrster.cn/blog-fnos.html https://github.com/nyzx0322/FnOS-GUI-Exploit-Tool https://github.com/wzqvip/FnOS-exploit/blob/main/TOKEN_FORGERY_FLOWCHART.md https://github.com/Mr-xn/Penetration_Testing_POC/blob/master/README.md
Related Vulnerabilities金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞技嘉科技|Gigabyte Control Center - Improper Access ControlPoChazelcast-management-exposure: Hazelcast Management Center - Configuration Exposurechangedetection.io /static/%2e%2e/flask_app.py 目录遍历漏洞(CVE-2026-25527)月子会所ERP管理云平台GetCustomerCenterReceiveList存在SQL注入漏洞金財通商務科技|Service Center - Insecure Direct Object Reference用友NC /uapws/service/nc.itf.msgcenter.IMsgCenterWebService SQL 注入漏洞关于NC系统IMsgCenterWebService的sql注入漏洞的安全通告PoCCVE-2024-32825: Simply Static - Information DisclosurePoCCVE-2025-11693: Export WP Page to Static HTML <= 4.3.4 - Cookie ExposurePoCCVE-2026-20079: Cisco Secure Firewall Management Center - Authentication BypassD-Link DNS-ShareCenter /cgi-bin/gui_mgr.cgi 命令执行漏洞(CVE-2026-4204)D-Link DNS-ShareCenter /cgi-bin/download_mgr.cgi 命令执行漏洞(CVE-2026-4197)