References https://www.twcert.org.tw/tw/cp-132-10099-0ad69-1.html https://tp2rc.tanet.edu.tw/node/1023 https://github.com/advisories/GHSA-7g8j-95mj-p92j https://www.twcert.org.tw/en/cp-139-10103-32121-2.html https://nvd.nist.gov/vuln/detail/CVE-2025-3711 https://www.cve.org/CVERecord?id=CVE-2025-3714 https://net.nthu.edu.tw/netsys/mailing:announcement:20250514_03?do=export_pdf https://cve.imfht.com/detail/CVE-2025-3714?lang=en
Related VulnerabilitiesPoCCVE-2026-9586: Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL InjectionPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-71362: Adobe Commerce/Magento - Customer Session Identity SwitchWordPress WebStack主题 /wp-admin/admin-ajax.php 文件上传漏洞(CVE-2026-1555)CentreStack 本地文件包含漏洞(CVE-2025-11371)全程云 /OA/api/2.0/HR/EntryApply/GetBaseData SQL 注入漏洞Apache CloudStack /client/api/ 默认口令漏洞Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)ERPNext /api/method/erpnext.stock.doctype.material_request.material_request.get_material_requests_based_on_supplier SQL 注入漏洞(CVE-2025-52039)PoCCVE-2025-62613: VDO.Ninja - DOM-Based Cross-Site ScriptingPoCservicestack-requestlogs: ServiceStack Request Logs - Unauthenticated AccessPoCCVE-2022-37932: HP Switch - Authentication BypassCisco Any Router and Switch 默认口令漏洞