References https://github.com/adminlove520/pocWiki/blob/main/Hytec%20Inter%20HWL-2511-SS%20popen.cgi%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/1zzZ/p/17637589.html https://stack.chaitin.com/vuldb/detail/a5ef42a0-8065-4bed-b4e3-7ded8f783108 https://neroteam.com/blog/hytec-inter-hwl-2511-ss-vulnerability-report https://www.ddpoc.com/DVB-2022-3865.html https://pentest-tools.com/vulnerabilities-exploits/hytec-inter-hwl-2511-ss-remote-command-execution_2143 https://cn-sec.com/archives/2266220.html https://avd.aliyun.com/detail?id=AVD-2022-36555 https://nvd.nist.gov/vuln/detail/CVE-2022-36553 https://access.redhat.com/security/cve/cve-2022-36553 https://gist.github.com/Nwqda/b27418ab801eb0b9cdbe8d042cb0249b https://www.scaprepo.com/relation.jsp?relationId=CVE-2022-36553&search=CVE-2022-36553&filter=
Related VulnerabilitiesPoCCVE-2026-8236: Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata DisclosureDocassemble /interview 文件包含漏洞(CVE-2024-27292)PoCunauth-mulesoft-dataweave: MuleSoft DataWeave Interactive Learning Environment - Unauthenticated Access朗速 ERP /Api/DataInterfaceApi.ashx SQL 注入漏洞PaperCut NG/MF /rpc/api/rest/master/user/createInternalUser;/keepalive 权限绕过漏洞 (CVE-2023-27351)Interlib /interlib/loan/PictureUpload 文件上传漏洞PoCCVE-2026-34486: Apache Tomcat Tribes EncryptInterceptor Bypass - Remote Code ExecutionPoCavaya-phone-default-login: Avaya Phone Web Interface - Default LoginPoC律师e通 /caseprocess/jsonData/interfaceData.ashx SQL 注入漏洞PoCsabnzbd-unauth-access: SABnzbd - Unauthenticated Web Interface AccessEveo URVE Web Manager /_internal/redirect.php 服务器端请求伪造漏洞(CVE-2025-35845)PoCpolycom-hdx-web-exposure: Polycom HDX - Web Interface Exposure九佳易 Interface/licx/PrivilegedCodeDestroy.asmx/UpdatePrivilegedState SQL 注入漏洞