References https://www.twcert.org.tw/tw/cp-132-10199-9c5c6-1.html https://cnc.nptu.edu.tw/p/406-1007-184965,r1042.php?Lang=zh-tw https://www.twcert.org.tw/newepaper/cp-151-10199-9c5c6-3.html https://www.sentinelone.com/vulnerability-database/cve-2025-6561/ https://securityonline.info/cve-2025-6561-cvss-9-8-hunt-electronic-dvr-vulnerability-exposes-admin-credentials-in-plaintext/ https://www.twcert.org.tw/tw/lp-132-1-6-20.html https://isms.ccu.edu.tw/p/404-1044-76477.php?Lang=zh-tw https://github.com/advisories/GHSA-7mcc-3f83-xx54
Related VulnerabilitiesPoCflowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API ExposurePoClangflow-api-exposure: Langflow - Unauthenticated API ExposurePoCCVE-2026-42221: Nginx UI <= 2.3.7 - Unauthenticated Installer ExposurePoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessPoCvictoriametrics-vmagent-api-exposure: VictoriaMetrics vmagent - Unauthenticated Targets ExposurePoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposurePoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCpypirc-credentials-exposure: Python .pypirc Credentials - Exposure中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞PoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information DisclosurePoCCVE-2026-3576: Planyo Online Reservation System <= 3.0 - Arbitrary File ReadPoCfastly-debug-headers: Fastly CDN Debug Headers Exposure