References https://www.twcert.org.tw/tw/cp-132-10578-c43b4-1.html https://www.dreamjtech.com/8027/ https://nvd.nist.gov/vuln/detail/CVE-2025-14304 https://thehackernews.com/2025/12/new-uefi-flaw-enables-early-boot-dma.html https://securityaffairs.com/185867/security/asrock-asus-gigabyte-msi-boards-vulnerable-to-pre-boot-memory-attacks.html https://www.asrock.com/support/Security.asp https://kb.cert.org/vuls/id/382314 https://www.securityweek.com/uefi-vulnerability-in-major-motherboards-enables-early-boot-attacks/
Related VulnerabilitiesArcserve Unified Data Protection /management/wizardLogin 权限绕过漏洞(CVE-2024-0799)友訊科技|DWM-222W Wi-Fi 6 USB 行動網路卡 - Brute-Force Protection BypassPoCCVE-2024-0799: Arcserve Unified Data Protection - Authentication BypassPoCCVE-2024-0801: Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dllPoCCVE-2021-24931: WordPress Secure Copy Content Protection and Content Locking <2.8.2 - SQL InjectionPoCCVE-2022-0787: Limit Login Attempts (Spam Protection) < 5.1 - SQL InjectionPoCCVE-2023-5089: Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)PoCCVE-2024-24759: MindsDB -DNS Rebinding SSRF Protection BypassPoCCVE-2023-3139: Protect WP Admin < 4.0 - Unauthenticated Protection BypassPoCstack-termination-disabled: CloudFormation Termination Protection - DisabledPoCelb-delete-protection-disabled: ELB Delete Protection - DisabledPoCs3-protection-disabled: GuardDuty S3 Protection - DisabledPoCaurora-delete-protect: Aurora Cluster Deletion Protection